VYPR

Sahana

by Sahana

CVEs (2)

  • CVE-2009-3625Oct 26, 2009
    risk 0.03cvss epss 0.06

    Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.

  • CVE-2010-1191Mar 31, 2010
    risk 0.00cvss epss 0.00

    Sahana disaster management system 0.6.2.2, and possibly other versions, allows remote attackers to bypass intended access restrictions and disable administrator authentication via a direct request to stream.php in an acl_enable_acl action to the admin module.