Vulnerabilities > Cafeengine

DATE CVE VULNERABILITY TITLE RISK
2009-02-13 CVE-2009-0574 SQL Injection vulnerability in Cafeengine Easycafeengine
SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-4604.
network
low complexity
cafeengine CWE-89
7.5
2008-10-18 CVE-2008-4605 SQL Injection vulnerability in Cafeengine Easycafeengine 1.1
SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) dish.php and (2) menu.php.
network
low complexity
cafeengine CWE-89
7.5
2008-10-18 CVE-2008-4604 SQL Injection vulnerability in Cafeengine Easycafeengine 1.1
SQL injection vulnerability in index.php in Easy CafeEngine 1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter.
network
low complexity
cafeengine CWE-89
7.5