Web Directory Pro
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2008-4091 | 0.03 | — | 0.01 | Sep 15, 2008 | SQL injection vulnerability in index.php in Web Directory Script 1.5.3 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action. | |||
| CVE-2008-3787 | 0.03 | — | 0.01 | Aug 26, 2008 | SQL injection vulnerability in listing_view.php in Web Directory Script 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter. | |||
| CVE-2006-5905 | 0.00 | — | 0.01 | Nov 15, 2006 | Web Directory Pro allows remote attackers to (1) backup the database and obtain the backup via a direct request to admin/backup_db.php or (2) modify configuration via a direct request to admin/options.php. |
- CVE-2008-4091Sep 15, 2008risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in Web Directory Script 1.5.3 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action.
- CVE-2008-3787Aug 26, 2008risk 0.03cvss —epss 0.01
SQL injection vulnerability in listing_view.php in Web Directory Script 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter.
- CVE-2006-5905Nov 15, 2006risk 0.00cvss —epss 0.01
Web Directory Pro allows remote attackers to (1) backup the database and obtain the backup via a direct request to admin/backup_db.php or (2) modify configuration via a direct request to admin/options.php.