VYPR

Mxcamarchive

by Infireal

CVEs (2)

  • CVE-2008-6956Aug 12, 2009
    risk 0.03cvss epss 0.01

    Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via the description parameter, which is executed by invocation of index.php. NOTE: some of these details are obtained from third party information.

  • CVE-2008-6955Aug 12, 2009
    risk 0.03cvss epss 0.02

    mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a direct request for archive/config.ini.