Vulnerabilities > Atcom > Netvolution > 1.0

DATE CVE VULNERABILITY TITLE RISK
2011-10-21 CVE-2009-5103 Cross-Site Scripting vulnerability in Atcom Netvolution 1.0
Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via the email variable.
network
atcom CWE-79
4.3
2011-10-21 CVE-2009-5102 SQL Injection vulnerability in Atcom Netvolution 1.0
SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL commands via the bpe_nid parameter.
network
low complexity
atcom CWE-89
7.5