RSS   Vulnerabilities for 'Rapid leech'   RSS

2011-09-23
 
CVE-2011-3798

CWE-200
 

 
Rapid Leech 2.3-v42-svn322 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by classes/pear.php and certain other files.

 
2009-03-25
 
CVE-2009-1091

CWE-79
 

 
Cross-site scripting (XSS) vulnerability in upload.php in Rapidleech rev.36 and earlier allows remote attackers to inject arbitrary web script or HTML via the uploaded parameter.

 
 
CVE-2009-1089

CWE-22
 

 
Absolute path traversal vulnerability in upload.php in Rapidleech rev.36 and earlier allows remote attackers to read arbitrary files via a base64-encoded absolute path in the filename parameter.

 

 >>> Vendor: Rapidleech 2 Products
Rapid leech
Rapidleech


Copyright 2024, cxsecurity.com

 

Back to Top