VYPR

Samepage

by Etouch

CVEs (2)

  • CVE-2015-2071Feb 24, 2015
    risk 0.04cvss epss 0.15

    Directory traversal vulnerability in cm/newui/blog/export.jsp in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the filepath parameter.

  • CVE-2015-2070Feb 24, 2015
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote attackers to execute arbitrary SQL commands via the catId parameter to cm/blogrss/feed.