VYPR
Vendor

Phpaddedit

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2008-6581Apr 2, 2009
    risk 0.03cvss epss 0.03

    login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.

  • CVE-2008-6313Feb 27, 2009
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in addedit-render.php in phpAddEdit 1.3, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a URL in the editform parameter. NOTE: PHP remote file inclusion attacks are also likely.