Vulnerabilities > Datachecknh > Sitepal
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-07-27 | CVE-2009-2616 | SQL Injection vulnerability in Datachecknh Sitepal 1.0 SQL injection vulnerability in z_admin_login.asp in DataCheck Solutions SitePal 1.x allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 7.5 |
2009-07-27 | CVE-2009-2615 | Cross-Site Scripting vulnerability in Datachecknh Sitepal 1.1 Multiple cross-site scripting (XSS) vulnerabilities in DataCheck Solutions SitePal 1.x allow remote attackers to inject arbitrary web script or HTML via the page parameter to (1) z_admin_login.asp, (2) z_forgot.asp, and possibly unspecified other components. | 4.3 |