Vulnerabilities > Jbook

DATE CVE VULNERABILITY TITLE RISK
2006-04-13 CVE-2006-1765 Cross-Site Scripting vulnerability in Jbook 1.3
Cross-site scripting (XSS) vulnerability in index.php in JBook 1.3 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
network
jbook
6.8
2006-04-12 CVE-2006-1743 SQL Injection vulnerability in Jbook 1.4
Multiple SQL injection vulnerabilities in form.php in JBook 1.4 allow remote attackers to execute arbitrary SQL commands via the (1) nom or (2) mail parameters.
network
low complexity
jbook
7.5