VYPR

Orca

by Boonex

CVEs (2)

  • CVE-2008-5167Nov 19, 2008
    risk 0.03cvss epss 0.04

    PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gConf[dir][layouts] parameter.

  • CVE-2009-2919Aug 21, 2009
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in Boonex Orca 2.0 and 2.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the topic title field.