SQL injection vulnerability in advcat.php in AbleSpace 1.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to eventsview.php and the (2) id parameter to eventsclndrview.php.
Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter to groupsprofile.php, (2) catid and (3) razdid parameters to advcat.php, and the (4) URL to blogsfull.php.