Vulnerabilities > Koan Software

DATE CVE VULNERABILITY TITLE RISK
2007-03-20 CVE-2006-7171 Improper Input Validation vulnerability in Koan Software Mega Mall
product_review.php in Koan Software Mega Mall allows remote attackers to obtain the installation path via a request with an empty value of the x[] parameter.
network
low complexity
koan-software CWE-20
5.0
2007-03-20 CVE-2006-7170 SQL Injection vulnerability in Koan Software Mega Mall
Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b) order-track.php.
network
low complexity
koan-software CWE-89
7.5