RSS   Vulnerabilities for 'Simple plantilla php'   RSS

2007-03-02
 
CVE-2007-1139

CWE-94
 

 
Unrestricted file upload vulnerability in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to upload arbitrary scripts via a filename with a double extension.

 
 
CVE-2007-1138

CWE-22
 

 
Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.

 

 >>> Vendor: Cromosoft 2 Products
Simple plantilla php
Facil helpdesk


Copyright 2024, cxsecurity.com

 

Back to Top