Vulnerabilities > CWM Design
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-12-27 | CVE-2006-6766 | SQL-Injection vulnerability in Cwm-Design Cwmexplorer 1.0 Multiple SQL injection vulnerabilities in cwmExplorer 1.1.0 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | 7.5 |
2006-12-27 | CVE-2006-6757 | Information Disclosure vulnerability in Cwm-Design Cwmexplorer 1.0 Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and source code, and obtain sensitive information via directory traversal sequences in the show_file parameter. | 7.8 |
2006-12-26 | CVE-2006-6738 | Code Injection vulnerability in Cwm-Design Cwmcounter PHP remote file inclusion vulnerability in statistic.php in cwmCounter 5.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | 6.8 |
2006-12-26 | CVE-2006-6732 | Code Injection vulnerability in Cwm-Design Cwmvote 1.0 PHP remote file inclusion vulnerability in archive.php in cwmVote 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the abs parameter. | 6.8 |