Vulnerabilities > CWM Design > Cwmexplorer > 1.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-12-27 | CVE-2006-6766 | SQL-Injection vulnerability in Cwm-Design Cwmexplorer 1.0 Multiple SQL injection vulnerabilities in cwmExplorer 1.1.0 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | 7.5 |
2006-12-27 | CVE-2006-6757 | Information Disclosure vulnerability in Cwm-Design Cwmexplorer 1.0 Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and source code, and obtain sensitive information via directory traversal sequences in the show_file parameter. | 7.8 |