Vulnerabilities > Alstrasoft > Webhost Directory > High

DATE CVE VULNERABILITY TITLE RISK
2008-12-17 CVE-2008-5650 SQL Injection vulnerability in Alstrasoft Webhost Directory NIL
SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute arbitrary SQL commands via the pwd parameter.
network
low complexity
alstrasoft CWE-89
7.5
2006-12-29 CVE-2006-6818 Unspecified vulnerability in Alstrasoft Webhost Directory
AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/config.
network
low complexity
alstrasoft
7.5
2006-05-26 CVE-2006-2616 SQL-Injection vulnerability in Alstrasoft Webhost Directory 1.2
SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to execute arbitrary SQL commands via the uri parameter.
network
low complexity
alstrasoft
7.5