Vulnerabilities > Cafuego

DATE CVE VULNERABILITY TITLE RISK
2011-11-01 CVE-2010-4986 SQL Injection vulnerability in Cafuego Simple Document Management System 1.1.4/1.1.5/1.1.6
SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute arbitrary SQL commands via the doc_id parameter.
network
low complexity
cafuego CWE-89
7.5
2009-02-21 CVE-2008-6236 SQL Injection vulnerability in Cafuego Simple Document Management System 1.1.4/1.1.5
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the login parameter.
network
low complexity
cafuego CWE-89
7.5
2009-02-20 CVE-2008-6220 SQL Injection vulnerability in Cafuego Simple Document Management System 1.1.4/1.1.5
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the pass parameter.
network
low complexity
cafuego CWE-89
7.5
2005-11-29 CVE-2005-3877 SQL Injection vulnerability in Cafuego Simple Document Management System 1.1.4/1.1.5/1.1.6
Multiple SQL injection vulnerabilities in Simple Document Management System (SDMS) 2.0-CVS and earlier allow remote attackers to execute arbitrary SQL commands via the (1) folder_id parameter in list.php and (2) mid parameter in a view action to messages.php.
network
low complexity
cafuego CWE-89
7.5