VYPR
Vendor

Acc

Products
4
CVEs
13
Across products
13
Status
Private

Products

4

Recent CVEs

13
  • CVE-2025-40657CriJun 10, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the codform parameter in /modules/forms/collectform.asp.

  • CVE-2025-40656CriJun 10, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the cod parameter in /administer/node-selection/data.asp.

  • CVE-2025-40655CriJun 10, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the name parameter in /antcatalogue.asp.

  • CVE-2025-40654CriJun 10, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the name and cod parameters in /antbuspre.asp.

  • CVE-2025-40662HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents of webroot/file, if navigating to a non-existent file.

  • CVE-2025-40661HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/selection.asp.

  • CVE-2025-40660HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/select node/data.asp?mode=catalogue&id1=1&id2=1session=&…

  • CVE-2025-40659HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelectionNetworks.asp.

  • CVE-2025-40658HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelection.asp.

  • CVE-2009-4906Jun 25, 2010
    risk 0.03cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in index.php in Acc PHP eMail 1.1 allows remote attackers to hijack the authentication of administrators for requests that change passwords.

  • CVE-2008-6293Feb 26, 2009
    risk 0.03cvss epss 0.03

    admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin."

  • CVE-2008-6291Feb 26, 2009
    risk 0.03cvss epss 0.02

    Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLETTERLOGIN cookie to "admin".

  • CVE-1999-0383Feb 2, 1999
    risk 0.00cvss epss 0.01

    ACC Tigris allows public access without a login.