Vulnerabilities > ASP Indir > Dora Emlak > 1.0

DATE CVE VULNERABILITY TITLE RISK
2007-07-25 CVE-2007-3990 SQL-Injection vulnerability in ASP Indir Dora Emlak 1.0
SQL injection vulnerability in default.asp in Dora Emlak 1.0, when the goster parameter is set to emlakdetay, allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
asp-indir
7.5
2007-07-25 CVE-2007-3989 Input Validation vulnerability in ASP Indir Dora Emlak 1.0
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in Dora Emlak 1.0, when the goster parameter is set to iletisim, allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz and (2) Soyadiniz parameters; and possibly other unspecified vectors.
network
asp-indir
4.3