Vulnerabilities > 21Degrees

DATE CVE VULNERABILITY TITLE RISK
2008-08-11 CVE-2008-3592 Code Injection vulnerability in 21Degrees Symphony
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/.
network
21degrees CWE-94
8.5
2008-08-11 CVE-2008-3591 SQL Injection vulnerability in 21Degrees Symphony
SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL commands via the sym_auth cookie in a /publish/filemanager/ request to index.php.
network
low complexity
21degrees CWE-89
7.5