Vulnerabilities > CWM Design

DATE CVE VULNERABILITY TITLE RISK
2006-12-27 CVE-2006-6766 SQL-Injection vulnerability in Cwm-Design Cwmexplorer 1.0
Multiple SQL injection vulnerabilities in cwmExplorer 1.1.0 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
cwm-design
7.5
2006-12-27 CVE-2006-6757 Information Disclosure vulnerability in Cwm-Design Cwmexplorer 1.0
Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and source code, and obtain sensitive information via directory traversal sequences in the show_file parameter.
network
low complexity
cwm-design
7.8
2006-12-26 CVE-2006-6738 Code Injection vulnerability in Cwm-Design Cwmcounter
PHP remote file inclusion vulnerability in statistic.php in cwmCounter 5.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
network
cwm-design CWE-94
6.8
2006-12-26 CVE-2006-6732 Code Injection vulnerability in Cwm-Design Cwmvote 1.0
PHP remote file inclusion vulnerability in archive.php in cwmVote 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the abs parameter.
network
cwm-design CWE-94
6.8