Vulnerabilities > Scriptmate

DATE CVE VULNERABILITY TITLE RISK
2006-12-15 CVE-2006-6595 SQL-Injection vulnerability in User Manager
Multiple SQL injection vulnerabilities in ScriptMate User Manager 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via "Manage Resources" and possibly other unspecified components.
network
low complexity
scriptmate
7.5
2006-12-15 CVE-2006-6594 SQL-Injection vulnerability in Scriptmate User Manager 2.0
SQL injection vulnerability in utilities/usermessages.asp in ScriptMate User Manager 2.0 allows remote attackers to execute arbitrary SQL commands via the mesid parameter.
network
low complexity
scriptmate
7.5
2006-12-15 CVE-2006-6583 Information Disclosure vulnerability in User Manager
ScriptMate User Manager 2.1 and earlier allow remote attackers to obtain sensitive information via unspecified vectors related to (1) the Logins box and (2) the Search box.
network
low complexity
scriptmate
7.5
2006-12-15 CVE-2006-6582 Cross-Site Scripting vulnerability in User Manager
Multiple cross-site scripting (XSS) vulnerabilities in ScriptMate User Manager 2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) members_username (user) and (2) members_password (password) fields in a login action in members/default.asp, and (3) the Search box.
network
scriptmate
6.8