Vulnerabilities > Xfairguy > Codeavalanche News > 1.2

DATE CVE VULNERABILITY TITLE RISK
2006-05-20 CVE-2006-2500 HTML Injection vulnerability in Xfairguy Codeavalanche News 1.2
Cross-site scripting (XSS) vulnerability in add_news.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to inject arbitrary web script or HTML via the Headline field.
network
xfairguy
6.8
2006-05-20 CVE-2006-2499 SQL Injection vulnerability in Xfairguy Codeavalanche News 1.2
SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitrary SQL commands via the password field.
network
low complexity
xfairguy
7.5