Vulnerabilities > Aspindir > Kisisel Radyo Script

DATE CVE VULNERABILITY TITLE RISK
2010-11-02 CVE-2010-4145 Permissions, Privileges, and Access Controls vulnerability in Aspindir Kisisel Radyo Script
Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for sevvo/eco23.mdb.
network
low complexity
aspindir CWE-264
5.0
2010-11-02 CVE-2010-4144 SQL Injection vulnerability in Aspindir Kisisel Radyo Script
SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL commands via the Id parameter.
network
low complexity
aspindir CWE-89
7.5