Vulnerabilities > Xfairguy > Codeavalanche News

DATE CVE VULNERABILITY TITLE RISK
2007-02-21 CVE-2007-1021 SQL Injection vulnerability in Xfairguy Codeavalanche News 1.X
SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary SQL commands via the CAT_ID parameter.
network
low complexity
xfairguy
critical
10.0
2006-05-20 CVE-2006-2500 HTML Injection vulnerability in Xfairguy Codeavalanche News 1.2
Cross-site scripting (XSS) vulnerability in add_news.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to inject arbitrary web script or HTML via the Headline field.
network
xfairguy
6.8
2006-05-20 CVE-2006-2499 SQL Injection vulnerability in Xfairguy Codeavalanche News 1.2
SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitrary SQL commands via the password field.
network
low complexity
xfairguy
7.5