VYPR

Postecards

by Dazzlindonna

CVEs (2)

  • CVE-2008-5560Dec 15, 2008
    risk 0.03cvss epss 0.06

    PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for postcards.mdb.

  • CVE-2008-5559Dec 15, 2008
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in sendcard.cfm in PostEcards allows remote attackers to execute arbitrary SQL commands via the cid parameter.