VYPR

Couponphp

by Couponphp

CVEs (2)

  • CVE-2014-10035Jan 13, 2015
    risk 0.04cvss epss 0.10

    Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to inject arbitrary web script or HTML via the (1) sEcho parameter to comments_paginate.php or (2) stores_paginate.php or the (3) affiliate_url, (4)…

  • CVE-2014-10034Jan 13, 2015
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execute arbitrary SQL commands via the (1) iDisplayLength or (2) iDisplayStart parameter to (a) comments_paginate.php or (b) stores_paginate.php in admin/ajax/.