Vulnerabilities > Datavore > Gyro
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-09-24 | CVE-2009-3349 | SQL Injection vulnerability in Datavore Gyro 5.0 SQL injection vulnerability in Datavore Gyro 5.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a cat action to the home component. | 7.5 |
2009-09-24 | CVE-2009-3348 | Cross-Site Scripting vulnerability in Datavore Gyro 5.0 Cross-site scripting (XSS) vulnerability in Datavore Gyro 5.0 allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a cat action to the home component. | 4.3 |