VYPR

Tutorials 2.0

by XOOPS

CVEs (2)

  • CVE-2008-1351Mar 17, 2008
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the Tutorials 2.1b module for XOOPS allows remote attackers to execute arbitrary SQL commands via the tid parameter to printpage.php, which is accessible directly or through a printpage action to index.php.

  • CVE-2003-0491Aug 7, 2003
    risk 0.00cvss epss 0.02

    The Tutorials 2.0 module in XOOPS and E-XOOPS allows remote attackers to execute arbitrary code by uploading a PHP file without a MIME image type, then directly accessing the uploaded file.