Vulnerabilities > Mealex

DATE CVE VULNERABILITY TITLE RISK
2007-06-06 CVE-2007-3064 Cross-Site Scripting vulnerability in Mealex MY Datebook
Cross-site scripting (XSS) vulnerability in diary.php in My Databook allows remote attackers to inject arbitrary web script or HTML via the year parameter.
network
mealex CWE-79
4.3
2007-06-06 CVE-2007-3063 SQL Injection vulnerability in Mealex MY Databook NIL
SQL injection vulnerability in diary.php in My Databook allows remote attackers to execute arbitrary SQL commands via the delete parameter.
network
low complexity
mealex CWE-89
7.5