Vulnerabilities > Hypersilence

DATE CVE VULNERABILITY TITLE RISK
2010-03-10 CVE-2009-4687 SQL Injection vulnerability in Hypersilence Silentum Guestbook 2.0.2
SQL injection vulnerability in silentum_guestbook.php in Silentum Guestbook 2.0.2 allows remote attackers to execute arbitrary SQL commands via the messageid parameter.
network
low complexity
hypersilence CWE-89
7.5
2009-04-28 CVE-2008-6764 Cross-Site Scripting vulnerability in Hypersilence Silentum Loginsys 1.0.0
Cross-site scripting (XSS) vulnerability in login.php in Silentum LoginSys 1.0.0 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
4.3
2009-04-28 CVE-2008-6763 Improper Authentication vulnerability in Hypersilence Silentum Loginsys 1.0.0
login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account's username.
network
low complexity
hypersilence CWE-287
7.5