VYPR

Downloadcontrol

by Jemscripts

CVEs (2)

  • CVE-2006-2552May 24, 2006
    risk 0.03cvss epss 0.01

    Jemscripts DownloadControl 1.0 allows remote attackers to obtain sensitive information via an invalid dcid parameter to dc.php, which leaks the pathname in an error message. NOTE: this was originally claimed to be SQL injection, but it is probably resultant from another issue in functions.php.

  • CVE-2006-2553May 24, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Jemscripts DownloadControl 1.0 allows remote attackers to inject arbitrary HTML or web script via the dcid parameter to dc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. This issue appears to be independent from a different issue that involves the same vector.