Vulnerabilities > Saral Kaushik

DATE CVE VULNERABILITY TITLE RISK
2006-01-21 CVE-2006-0346 Input Validation vulnerability in Saral Kaushik Saralblog 1.0
Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is not properly handled in the comment function in functions.php.
network
saral-kaushik
4.3
2006-01-21 CVE-2006-0345 Input Validation vulnerability in Saral Kaushik Saralblog 1.0
Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php.
network
low complexity
saral-kaushik
7.5