Vulnerabilities > Radscripts > Radnics

DATE CVE VULNERABILITY TITLE RISK
2010-03-10 CVE-2009-4697 Cross-Site Scripting vulnerability in Radscripts Radnics 5
Multiple cross-site scripting (XSS) vulnerabilities in index.php in RadNICS Gold 5 allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter in a ulist action and the (2) fid parameter in a view_forum action.
network
radscripts CWE-79
4.3
2010-03-10 CVE-2009-4696 SQL Injection vulnerability in Radscripts Radnics 5
SQL injection vulnerability in index.php in RadNICS Gold 5 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action.
network
low complexity
radscripts CWE-89
7.5