Vulnerabilities > Cafuego
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2011-11-01 | CVE-2010-4986 | SQL Injection vulnerability in Cafuego Simple Document Management System 1.1.4/1.1.5/1.1.6 SQL injection vulnerability in detail.php in Simple Document Management System (SDMS) allows remote attackers to execute arbitrary SQL commands via the doc_id parameter. | 7.5 |
2009-02-21 | CVE-2008-6236 | SQL Injection vulnerability in Cafuego Simple Document Management System 1.1.4/1.1.5 SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the login parameter. | 7.5 |
2009-02-20 | CVE-2008-6220 | SQL Injection vulnerability in Cafuego Simple Document Management System 1.1.4/1.1.5 SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the pass parameter. | 7.5 |
2005-11-29 | CVE-2005-3877 | SQL Injection vulnerability in Cafuego Simple Document Management System 1.1.4/1.1.5/1.1.6 Multiple SQL injection vulnerabilities in Simple Document Management System (SDMS) 2.0-CVS and earlier allow remote attackers to execute arbitrary SQL commands via the (1) folder_id parameter in list.php and (2) mid parameter in a view action to messages.php. | 7.5 |