VYPR

Flexphpdirectory

by China On Site

CVEs (2)

  • CVE-2008-6750Apr 24, 2009
    risk 0.03cvss epss 0.03

    Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photo/.

  • CVE-2008-6749Apr 24, 2009
    risk 0.03cvss epss 0.00

    Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) checkuser and (2) checkpass parameters.