Vulnerabilities > Construtiva

DATE CVE VULNERABILITY TITLE RISK
2014-05-20 CVE-2014-3749 SQL Injection vulnerability in Construtiva CIS Manager CMS
SQL injection vulnerability in Construtiva CIS Manager allows remote attackers to execute arbitrary SQL commands via the email parameter to autenticar/lembrarlogin.asp.
network
low complexity
construtiva CWE-89
7.5
2014-04-11 CVE-2014-2847 SQL Injection vulnerability in Construtiva CIS Manager CMS
SQL injection vulnerability in default.asp in CIS Manager CMS allows remote attackers to execute arbitrary SQL commands via the TroncoID parameter.
network
low complexity
construtiva CWE-89
7.5