Vulnerabilities > WEC MAP Project

DATE CVE VULNERABILITY TITLE RISK
2014-10-03 CVE-2014-6296 Cross-Site Scripting vulnerability in WEC MAP Project WEC MAP 3.0.0/3.0.1/3.0.2
Cross-site scripting (XSS) vulnerability in the WEC Map (wec_map) extension before 3.0.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
2014-10-03 CVE-2014-6295 SQL Injection vulnerability in WEC MAP Project WEC MAP 3.0.0/3.0.1/3.0.2
SQL injection vulnerability in the WEC Map (wec_map) extension before 3.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
wec-map-project CWE-89
7.5