VYPR

Registration Manager

by Dmxready

CVEs (2)

  • CVE-2009-2238Jun 27, 2009
    risk 0.03cvss epss 0.03

    Unrestricted file upload vulnerability in includes/shared_scripts/wysiwyg_editor/assetmanager/assetmanager.asp in DMXReady Registration Manager 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in assets/webblogmanager.

  • CVE-2009-1821May 29, 2009
    risk 0.03cvss epss 0.05

    DMXReady Registration Manager 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for databases/webblogmanager.mdb.