Vulnerabilities > Joomlaboat

DATE CVE VULNERABILITY TITLE RISK
2014-07-21 CVE-2014-4960 SQL Injection vulnerability in Joomlaboat COM Youtubegallery
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.
network
low complexity
joomlaboat CWE-89
7.5
2014-04-25 CVE-2013-5956 Cross-Site Scripting vulnerability in Joomlaboat COM Youtubegallery 3.4.0
Cross-site scripting (XSS) vulnerability in includes/flvthumbnail.php in the Youtube Gallery (com_youtubegallery) component 3.4.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the videofile parameter.
network
joomlaboat CWE-79
4.3