RSS   Vulnerabilities for 'Dir2web'   RSS

2012-08-12
 
CVE-2012-4070

CWE-89
 

 
SQL injection vulnerability in system/src/dispatcher.php in Dir2web 3.0 allows remote attackers to execute arbitrary SQL commands via the oid parameter in a homepage action to index.php.

 
 
CVE-2012-4069

CWE-264
 

 
Dir2web 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database via a direct request for system/db/website.db.

 


Copyright 2024, cxsecurity.com

 

Back to Top