Vulnerabilities > Auracms > Auracms > 1.5.rc

DATE CVE VULNERABILITY TITLE RISK
2007-09-17 CVE-2007-4908 Path Traversal vulnerability in Auracms
Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a ..
network
low complexity
auracms CWE-22
7.5
2007-09-11 CVE-2007-4804 SQL Injection vulnerability in Auracms 1.5Rc
Multiple SQL injection vulnerabilities in AuraCMS 1.5rc allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) hal.php, (2) cetak.php, (3) lihat.php, (4) pesan.php, and (5) teman.php, different vectors than CVE-2007-4171.
network
low complexity
auracms CWE-89
7.5