RSS   Vulnerabilities for 'Frax.dk php recommend'   RSS

2009-05-22
 
CVE-2009-1781

CWE-94
 

 
Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inject arbitrary PHP code into phpre_config.php via the form_aula parameter.

 
 
CVE-2009-1780

CWE-264
 

 
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.

 
 
CVE-2009-1779

CWE-94
 

 
PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the form_include_template parameter.

 


Copyright 2024, cxsecurity.com

 

Back to Top