Vulnerabilities > CWM Design > Cwmexplorer

DATE CVE VULNERABILITY TITLE RISK
2006-12-27 CVE-2006-6766 SQL-Injection vulnerability in Cwm-Design Cwmexplorer 1.0
Multiple SQL injection vulnerabilities in cwmExplorer 1.1.0 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
cwm-design
7.5
2006-12-27 CVE-2006-6757 Information Disclosure vulnerability in Cwm-Design Cwmexplorer 1.0
Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and source code, and obtain sensitive information via directory traversal sequences in the show_file parameter.
network
low complexity
cwm-design
7.8