Vulnerabilities > Onnogroen
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2010-02-22 | CVE-2009-4651 | Cross-Site Scripting vulnerability in Onnogroen COM Webeecomment 1.1.1/1.2/2.0 Multiple cross-site scripting (XSS) vulnerabilities in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) color, (2) img, or (3) url BBCode tags in unspecified vectors. | 4.3 |
2010-02-22 | CVE-2009-4650 | SQL Injection vulnerability in Onnogroen COM Webeecomment 1.1.1/1.2/2.0 SQL injection vulnerability in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a default action to index2.php. | 7.5 |