RSS   Vulnerabilities for 'Siche search module'   RSS

2012-08-31
 
CVE-2012-4744

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in ssearch.php in the Siche search module 0.5 for Zeroboard allows remote attackers to inject arbitrary web script or HTML via the search parameter.

 
 
CVE-2012-4743

 

 
Multiple SQL injection vulnerabilities in ssearch.php in Siche search module 0.5 for Zeroboard allow remote attackers to execute arbitrary SQL commands via the (1) ss, (2) sm, (3) align, or (4) category parameters.

 


Copyright 2024, cxsecurity.com

 

Back to Top