Vulnerabilities > Brooky

DATE CVE VULNERABILITY TITLE RISK
2003-08-18 CVE-2003-0586 Remote Security vulnerability in Brooky Estore 1.0.2B
Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php.
network
low complexity
brooky
7.5
2003-08-18 CVE-2003-0585 SQL-Injection vulnerability in Brooky Estore 1.0.2B
SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters.
network
low complexity
brooky
7.5