VYPR

Thatware

by Thatware

CVEs (3)

  • CVE-2006-4213Aug 17, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in config.php in David Kent Norman Thatware 0.4.6 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.

  • CVE-2002-2252Dec 31, 2002
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in auth.inc.php in Thatware 0.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via a base64-encoded user parameter.

  • CVE-2002-2297Dec 31, 2002
    risk 0.00cvss —epss 0.01

    PHP remote file inclusion vulnerability in artlist.php in Thatware 0.5.2 and 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.