Vulnerabilities > Bioinformatics

DATE CVE VULNERABILITY TITLE RISK
2012-09-20 CVE-2011-5183 SQL Injection vulnerability in Bioinformatics Ordersys
Multiple SQL injection vulnerabilities in OrderSys 1.6.4 and earlier allow remote attackers to execute arbitrary SQL commands via the where_clause parameter to (1) index.php, (2) index_long.php, or (3) index_short.php in ordering/interface_creator/.
network
low complexity
bioinformatics CWE-89
7.5
2009-02-03 CVE-2009-0404 Cross-Site Scripting vulnerability in Bioinformatics Htmlawed
Multiple cross-site scripting (XSS) vulnerabilities in Bioinformatics htmLawed 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via invalid Cascading Style Sheets (CSS) expressions in the style attribute, which is processed by Internet Explorer 7.
4.3