VYPR

Vcard4j

by Vcard4j

CVEs (2)

  • CVE-2004-1828Dec 31, 2004
    risk 0.03cvss epss 0.02

    Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php.

  • CVE-2004-1794Dec 31, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the VCard4J Toolkit allows remote attackers to inject arbitrary web script or HTML via the NICKNAME tag in a vCard.