Vulnerabilities > Alstrasoft > Webhost Directory > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-12-17 | CVE-2008-5650 | SQL Injection vulnerability in Alstrasoft Webhost Directory NIL SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute arbitrary SQL commands via the pwd parameter. | 7.5 |
2006-12-29 | CVE-2006-6818 | Unspecified vulnerability in Alstrasoft Webhost Directory AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/config. | 7.5 |
2006-05-26 | CVE-2006-2616 | SQL-Injection vulnerability in Alstrasoft Webhost Directory 1.2 SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to execute arbitrary SQL commands via the uri parameter. | 7.5 |