Vulnerabilities > Dataparksearch

DATE CVE VULNERABILITY TITLE RISK
2006-11-04 CVE-2006-5723 SQL Injection vulnerability in DataparkSearch Malformed Hostname
SQL injection vulnerability in DataparkSearch Engine 4.42 and earlier allows remote attackers to execute arbitrary SQL commands via a malformed hostname in a URL.
network
low complexity
dataparksearch
7.5
2006-02-13 CVE-2006-0649 Cross-Site Scripting vulnerability in DataparkSearch Engine Search Template
Cross-site scripting (XSS) vulnerability in DataparkSearch before 4.37 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
dataparksearch
4.3