VYPR

A Faq

by Alan Ward

CVEs (2)

  • CVE-2006-6831Dec 31, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in faqDsp.asp in aFAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the catcode parameter.

  • CVE-2005-4064Dec 7, 2005
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) faqid parameter to faqDspItem.asp and (2) catcode parameter to faqDsp.asp.