Vulnerabilities > Xigla > Absolute FAQ Manager NET

DATE CVE VULNERABILITY TITLE RISK
2009-07-14 CVE-2008-6854 Improper Authentication vulnerability in Xigla Absolute FAQ Manager .Net 6.0
Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
network
low complexity
xigla CWE-287
7.5
2006-03-28 CVE-2006-1416 Cross-Site Scripting vulnerability in Absolute FAQ Manager
Cross-site scripting (XSS) vulnerability in afmsearch.aspx in Absolute FAQ Manager .NET 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the question parameter.
network
xigla
4.3