VYPR

PHP Volunteer Management

by Shawn Bradley

CVEs (2)

  • CVE-2012-6505Jan 24, 2013
    risk 0.04cvss epss 0.07

    Cross-site scripting (XSS) vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

  • CVE-2012-6504Jan 24, 2013
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.