VYPR

Recipes Listing Portal

by Scriptsfeed

CVEs (2)

  • CVE-2010-5039Nov 2, 2011
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information.

  • CVE-2008-6943Aug 12, 2009
    risk 0.03cvss epss 0.02

    Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the file in pictures/.