Vulnerabilities > Infomining
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-07-31 | CVE-2008-3394 | Cross-Site Scripting vulnerability in Infomining Bookmine Multiple cross-site scripting (XSS) vulnerabilities in search.cfm in BookMine allow remote attackers to inject arbitrary web script or HTML via the (1) gallery and (2) search_string parameters. | 4.3 |
2008-07-31 | CVE-2008-3393 | SQL Injection vulnerability in Infomining Bookmine SQL injection vulnerability in events.cfm in BookMine allows remote attackers to execute arbitrary SQL commands via the events_id parameter. | 7.5 |