VYPR

Xm Memberstats

Sign in to watch

by XOOPS

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2008-10630.000.00Feb 28, 2008Cross-site scripting (XSS) vulnerability index.php in the XM-Memberstats (xmmemberstats) module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the sortby parameter.
CVE-2008-10650.000.00Feb 28, 2008Multiple SQL injection vulnerabilities in index.php in the XM-Memberstats (xmmemberstats) 2.0e module for XOOPS allow remote attackers to execute arbitrary SQL commands via the (1) letter or (2) sortby parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.