VYPR

Business Portal

by Uiga

CVEs (2)

  • CVE-2010-1049Mar 23, 2010
    risk 0.03cvss epss 0.00

    Multiple SQL injection vulnerabilities in Uiga Business Portal allow remote attackers to execute arbitrary SQL commands via the (1) noentryid parameter to blog/index.php and the (2) p parameter to index2.php.

  • CVE-2010-1048Mar 23, 2010
    risk 0.03cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in blog/index.php in Uiga Business Portal allows remote attackers to inject arbitrary web script or HTML via the textcomment parameter (aka the Comment Box) in a noentryid action. NOTE: some of these details are obtained from third party information.