VYPR

Simple Plantilla PHP

by Cromosoft

CVEs (2)

  • CVE-2007-1138Mar 2, 2007
    risk 0.03cvss epss 0.03

    Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to list arbitrary directories, and read arbitrary files, via an absolute pathname in the nfolder parameter.

  • CVE-2007-1139Mar 2, 2007
    risk 0.00cvss epss 0.02

    Unrestricted file upload vulnerability in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to upload arbitrary scripts via a filename with a double extension.