Vulnerabilities > Ezboxx

DATE CVE VULNERABILITY TITLE RISK
2007-01-16 CVE-2007-0266 Cross-Site Scripting vulnerability in Ezboxx Portal System Beta0.7.6
SQL injection vulnerability in boxx/ShowAppendix.asp in Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the iid parameter.
network
low complexity
ezboxx
7.5
2007-01-16 CVE-2007-0265 Cross-Site Scripting vulnerability in Portal System Beta
Multiple cross-site scripting (XSS) vulnerabilities in Ezboxx Portal System Beta 0.7.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pic parameter to custom/piczoom.asp, (2) the nocatname parameter to boxx/user-upload.asp, or (3) the iid parameter to indexes/newscomments.asp.
network
ezboxx
6.8
2007-01-16 CVE-2007-0259 Information Exposure vulnerability in Ezboxx Portal System Beta0.7.6
Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via an invalid cat parameter to boxx/knowledgebase.asp, which reveals the path in an error message.
network
low complexity
ezboxx CWE-200
7.8