Vulnerabilities > Ajsquare > AJ Article > High

DATE CVE VULNERABILITY TITLE RISK
2009-08-24 CVE-2008-7051 Improper Authentication vulnerability in Ajsquare AJ Article
AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesuspend.php, (4) site.php, (5) statistics.php, (6) mail.php, (7) category.php, (8) subcategory.php, (9) changepassword.php, (10) polling.php, and (11) logo.php in admin/.
network
low complexity
ajsquare CWE-287
7.5
2009-04-14 CVE-2008-6721 SQL Injection vulnerability in Ajsquare AJ Article
SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName parameter (aka the username field).
network
low complexity
ajsquare CWE-89
7.5