VYPR

Free Simple Software

by Dustincowell

CVEs (2)

  • CVE-2010-4298Nov 26, 2010
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in the download module in Free Simple Software 1.0 allows remote attackers to execute arbitrary SQL commands via the downloads_id parameter in a download_now action to index.php.

  • CVE-2010-4311Nov 26, 2010
    risk 0.00cvss epss 0.00

    Free Simple Software 1.0 stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information.