Vulnerabilities > Isolsoft > Support Center > 2.5

DATE CVE VULNERABILITY TITLE RISK
2010-01-04 CVE-2009-4542 Cross-Site Scripting vulnerability in Isolsoft Support Center 2.5
Cross-site scripting (XSS) vulnerability in newticket.php in IsolSoft Support Center 2.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
network
isolsoft CWE-79
4.3
2010-01-04 CVE-2009-4541 Code Injection vulnerability in Isolsoft Support Center 2.5
Multiple PHP remote file inclusion vulnerabilities in IsolSoft Support Center 2.5 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) newticket.php or (2) rempass.php, or a URL in the lang parameter in an adduser action to (3) index.php.
network
low complexity
isolsoft CWE-94
7.5