Openconstructor Project / Openconstructor
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2012-3873 | Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1… | MEDIUM | 6.5 | Dec 28, 2012 |
| CVE-2012-3872 | Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result… | MEDIUM | 4.3 | Dec 28, 2012 |
| CVE-2012-3871 | Cross-site scripting (XSS) vulnerability in data/hybrid/i_hybrid.php in Open Constructor 3.12.0 allows remote authenticated users to inject arbitrary web scrip… | LOW | 3.5 | Dec 28, 2012 |
| CVE-2012-3870 | Multiple cross-site scripting (XSS) vulnerabilities in objects/createobject.php in Open Constructor 3.12.0 allow remote authenticated users to inject arbitrary… | LOW | 3.5 | Dec 28, 2012 |
Showing 1 to 4 of 4 CVEs