Vulnerabilities > Customerparadigm
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2010-07-12 | CVE-2010-2685 | Permissions, Privileges, and Access Controls vulnerability in Customerparadigm Pagedirector CMS siteadmin/adduser.php in Customer Paradigm PageDirector CMS does not properly restrict access, which allows remote attackers to bypass intended restrictions and add administrative users via a direct request. | 7.5 |
2010-07-12 | CVE-2010-2684 | SQL Injection vulnerability in Customerparadigm Pagedirector CMS SQL injection vulnerability in index.php in Customer Paradigm PageDirector CMS allows remote attackers to execute arbitrary SQL commands via the id parameter. | 7.5 |
2010-07-12 | CVE-2010-2683 | SQL Injection vulnerability in Customerparadigm Pagedirector CMS SQL injection vulnerability in result.php in Customer Paradigm PageDirector CMS allows remote attackers to execute arbitrary SQL commands via the sub_catid parameter. | 7.5 |