RSS   Vulnerabilities for 'Phpeasydata'   RSS

2008-07-03
 
CVE-2008-2995

CWE-89
 

 
Multiple SQL injection vulnerabilities in PHPEasyData 1.5.4 allow remote attackers to execute arbitrary SQL commands via (1) the annuaire parameter to annuaire.php or (2) the username field in admin/login.php.

 
 
CVE-2008-2994

CWE-79
 

 
Multiple cross-site scripting (XSS) vulnerabilities in PHPEasyData 1.5.4 allow remote attackers to inject arbitrary web script or HTML via the (1) annuaire parameter to (a) last_records.php and (b) annuaire.php and the (2) by and (3) cat_id parameters to annuaire.php.

 
2008-05-08
 
CVE-2008-2113

CWE-89
 

 
SQL injection vulnerability in annuaire.php in PHPEasyData 1.5.4 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

 


Copyright 2024, cxsecurity.com

 

Back to Top