Xfairguy / Codeavalanche News
3 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2007-1021 | SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary SQL commands via the CAT_ID parameter. | HIGH | 10.0 | Feb 21, 2007 |
| CVE-2006-2500 | Cross-site scripting (XSS) vulnerability in add_news.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to inject arbitrary web script or HTML via… | MEDIUM | 6.8 | May 20, 2006 |
| CVE-2006-2499 | SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitrary SQL commands via the password field. | HIGH | 7.5 | May 20, 2006 |
Showing 1 to 3 of 3 CVEs