RSS   Vulnerabilities for 'Rechnungszentrale'   RSS

2006-04-21
 
CVE-2006-1955

 

 
PHP remote file inclusion vulnerability in authent.php4 in Nicolas Fischer (aka NFec) RechnungsZentrale V2 1.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter.

 
 
CVE-2006-1954

 

 
SQL injection vulnerability in authent.php4 in Nicolas Fischer (aka NFec) RechnungsZentrale V2 1.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the User field.

 


Copyright 2024, cxsecurity.com

 

Back to Top