RSS   Vulnerabilities for 'Aproxengine'   RSS

2008-07-24
 
CVE-2008-3291

CWE-89
 

 
SQL injection vulnerability in index.php in AproxEngine (aka Aprox CMS Engine) 5.1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

 
2008-06-27
 
CVE-2008-2895

CWE-22
 

 
Directory traversal vulnerability in index.php in AproxEngine 5.1.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

 

 >>> Vendor: Aprox 2 Products
Aproxengine
Aprox cms engine


Copyright 2024, cxsecurity.com

 

Back to Top