Vulnerabilities > Attachmax

DATE CVE VULNERABILITY TITLE RISK
2008-09-24 CVE-2008-4207 Information Exposure vulnerability in Attachmax Dolphin 2.1.0
Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive information via a direct request, which invokes the phpinfo function.
network
low complexity
attachmax CWE-200
5.0
2008-09-24 CVE-2008-4206 Code Injection vulnerability in Attachmax Dolphin 2.1.0
PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rel_path parameter.
network
low complexity
attachmax CWE-94
7.5
2008-09-24 CVE-2008-4205 SQL Injection vulnerability in Attachmax Dolphin 2.1.0
SQL injection vulnerability in search.php Attachmax Dolphin 2.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a Search action to index.php.
network
low complexity
attachmax CWE-89
7.5