VYPR

Letterbox

by Maarch

CVEs (2)

  • CVE-2015-1587Feb 19, 2015
    risk 0.07cvss epss 0.44

    Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a request to a predictable filename…

  • CVE-2014-8995Nov 20, 2014
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie.