VYPR

Contact Manager Pro

by Ocean12

CVEs (3)

  • CVE-2008-6370Mar 2, 2009
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to inject arbitrary web script or HTML via the DisplayFormat parameter.

  • CVE-2008-6369Mar 2, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitrary SQL commands via the Sort parameter.

  • CVE-2008-5127Nov 18, 2008
    risk 0.00cvss epss 0.01

    Ocean12 Contact Manager Pro 1.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12con.mdb.