Vulnerabilities > Customerparadigm

DATE CVE VULNERABILITY TITLE RISK
2010-07-12 CVE-2010-2685 Permissions, Privileges, and Access Controls vulnerability in Customerparadigm Pagedirector CMS
siteadmin/adduser.php in Customer Paradigm PageDirector CMS does not properly restrict access, which allows remote attackers to bypass intended restrictions and add administrative users via a direct request.
network
low complexity
customerparadigm CWE-264
7.5
2010-07-12 CVE-2010-2684 SQL Injection vulnerability in Customerparadigm Pagedirector CMS
SQL injection vulnerability in index.php in Customer Paradigm PageDirector CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
customerparadigm CWE-89
7.5
2010-07-12 CVE-2010-2683 SQL Injection vulnerability in Customerparadigm Pagedirector CMS
SQL injection vulnerability in result.php in Customer Paradigm PageDirector CMS allows remote attackers to execute arbitrary SQL commands via the sub_catid parameter.
network
low complexity
customerparadigm CWE-89
7.5