Vulnerabilities > Datachecknh > Sitepal

DATE CVE VULNERABILITY TITLE RISK
2009-07-27 CVE-2009-2616 SQL Injection vulnerability in Datachecknh Sitepal 1.0
SQL injection vulnerability in z_admin_login.asp in DataCheck Solutions SitePal 1.x allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
datachecknh CWE-89
7.5
2009-07-27 CVE-2009-2615 Cross-Site Scripting vulnerability in Datachecknh Sitepal 1.1
Multiple cross-site scripting (XSS) vulnerabilities in DataCheck Solutions SitePal 1.x allow remote attackers to inject arbitrary web script or HTML via the page parameter to (1) z_admin_login.asp, (2) z_forgot.asp, and possibly unspecified other components.
4.3