RSS   Vulnerabilities for 'Bookmine'   RSS

2008-07-31
 
CVE-2008-3394

CWE-79
 

 
Multiple cross-site scripting (XSS) vulnerabilities in search.cfm in BookMine allow remote attackers to inject arbitrary web script or HTML via the (1) gallery and (2) search_string parameters.

 
 
CVE-2008-3393

CWE-89
 

 
SQL injection vulnerability in events.cfm in BookMine allows remote attackers to execute arbitrary SQL commands via the events_id parameter.

 


Copyright 2024, cxsecurity.com

 

Back to Top