Vulnerabilities > Codefixer

DATE CVE VULNERABILITY TITLE RISK
2009-03-02 CVE-2008-6374 Permissions, Privileges, and Access Controls vulnerability in Codefixer Mailinglistpro
CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to db/MailingList.mdb.
network
low complexity
codefixer CWE-264
5.0
2009-02-05 CVE-2009-0431 SQL Injection vulnerability in Codefixer Linkspro NIL
SQL injection vulnerability in Default.asp in LinksPro Standard Edition allows remote attackers to execute arbitrary SQL commands via the OrderDirection parameter.
network
low complexity
codefixer CWE-89
7.5