VYPR

Machform

by Machform

CVEs (3)

  • CVE-2013-4949Jul 29, 2013
    risk 0.04cvss epss 0.09

    Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in the upload form's directory in data/.

  • CVE-2013-4950Jul 29, 2013
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the element_2 parameter.

  • CVE-2013-4948Jul 29, 2013
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter.