Vulnerabilities (CVE)

Filtered by vendor Iwebnegar Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-4496 1 Iwebnegar 1 Iwebnegar 2024-02-04 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.
CVE-2006-4497 1 Iwebnegar 1 Iwebnegar 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2004-1402 1 Iwebnegar 1 Iwebnegar 2024-02-04 10.0 HIGH N/A
SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string parameter for index.php, (2) comments.php, or (3) the administrator login page.