Vulnerabilities > David Barrett > Qwikiwiki > 1.5

DATE CVE VULNERABILITY TITLE RISK
2006-03-13 CVE-2006-1196 Cross-Site Scripting vulnerability in David Barrett Qwikiwiki 1.4/1.5/1.5.1
Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) from and (2) help parameters to (a) index.php; (3) action, (4) page, (5) debug, (6) help, (7) username, or (8) password parameters to (b) login.php; the (7) help parameter to (c) pageindex.php; or (8) help parameter to (d) recentchanges.php.
network
david-barrett
4.3
2006-02-15 CVE-2006-0699 Cross-Site Scripting vulnerability in QwikiWiki
Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter.
network
david-barrett
4.3