VYPR
Vendor

Dustincowell

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2010-4298Nov 26, 2010
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in the download module in Free Simple Software 1.0 allows remote attackers to execute arbitrary SQL commands via the downloads_id parameter in a download_now action to index.php.

  • CVE-2010-3742Oct 5, 2010
    risk 0.03cvss epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) meta or (2) phpincdir parameter, a different issue than CVE-2010-3307.

  • CVE-2010-3307Oct 5, 2010
    risk 0.03cvss epss 0.01

    Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) body, (2) footer, (3) header, (4) menu_left, or (5) menu_right parameter.

  • CVE-2010-4311Nov 26, 2010
    risk 0.00cvss epss 0.00

    Free Simple Software 1.0 stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information.