Vulnerabilities > David Barrett > Qwikiwiki > 1.5
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-03-13 | CVE-2006-1196 | Cross-Site Scripting vulnerability in David Barrett Qwikiwiki 1.4/1.5/1.5.1 Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) from and (2) help parameters to (a) index.php; (3) action, (4) page, (5) debug, (6) help, (7) username, or (8) password parameters to (b) login.php; the (7) help parameter to (c) pageindex.php; or (8) help parameter to (d) recentchanges.php. network david-barrett | 4.3 |
2006-02-15 | CVE-2006-0699 | Cross-Site Scripting vulnerability in QwikiWiki Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter. network david-barrett | 4.3 |