Vulnerabilities > Ocomon

DATE CVE VULNERABILITY TITLE RISK
2005-12-31 CVE-2005-4664 SQL-Injection vulnerability in Ocomon 1.21
SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the logon page, a different vulnerability than CVE-2005-4662.
network
low complexity
ocomon
5.0
2005-12-31 CVE-2005-4663 Cross-Site Scripting vulnerability in OcoMon
Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
network
ocomon
4.3
2005-12-31 CVE-2005-4662 SQL Injection vulnerability in OcoMon
Multiple SQL injection vulnerabilities in OcoMon 1.20, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via unknown attack vectors in an unspecified input form, a different vulnerability than CVE-2005-4664.
network
low complexity
ocomon
5.0