Vulnerabilities > Logaholic

DATE CVE VULNERABILITY TITLE RISK
2007-12-28 CVE-2007-6560 Cross-Site Scripting vulnerability in Logaholic 0
Multiple cross-site scripting (XSS) vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to inject arbitrary web script or HTML via (1) the newconfname parameter to profiles.php or (2) the conf parameter to index.php.
network
logaholic CWE-79
4.3
2007-12-28 CVE-2007-6559 SQL Injection vulnerability in Logaholic 0
Multiple SQL injection vulnerabilities in Logaholic before 2.0 RC8 allow remote attackers to execute arbitrary SQL commands via (1) the from parameter to index.php or (2) the page parameter to update.php.
network
low complexity
logaholic CWE-89
7.5