Vulnerabilities > Onnogroen

DATE CVE VULNERABILITY TITLE RISK
2010-02-22 CVE-2009-4651 Cross-Site Scripting vulnerability in Onnogroen COM Webeecomment 1.1.1/1.2/2.0
Multiple cross-site scripting (XSS) vulnerabilities in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) color, (2) img, or (3) url BBCode tags in unspecified vectors.
4.3
2010-02-22 CVE-2009-4650 SQL Injection vulnerability in Onnogroen COM Webeecomment 1.1.1/1.2/2.0
SQL injection vulnerability in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a default action to index2.php.
network
low complexity
onnogroen joomla CWE-89
7.5