VYPR

Advertisementmanager

Sign in to watch

by Advertisementmanager

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2010-11060.030.04Mar 25, 2010PHP remote file inclusion vulnerability in cgi/index.php in AdvertisementManager 3.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the req parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.
CVE-2010-11050.000.00Mar 25, 2010Cross-site scripting (XSS) vulnerability in cgi/index.php in AdvertisementManager 3.1.0 and 3.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter.