MidnightBSD

Advisories for tux_racer

CVE-2005-4732 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Tux Racer TuxBank 0.7x and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) description parameters.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
tux_racer tuxbank 0.73
tux_racer tuxbank 0.77
tux_racer tuxbank 0.76
tux_racer tuxbank 0.74
tux_racer tuxbank 0.72
tux_racer tuxbank 0.75
tux_racer tuxbank 0.8
CVE-2005-4768 HIGH

SQL injection vulnerability in manage_account.php in Tux Racer TuxBank 0.7x and 0.8 allows remote attackers to execute arbitrary SQL commands via the id parameter in a manageaccount action to index.php.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
tux_racer tuxbank 0.7x
tux_racer tuxbank 0.8