Vulnerabilities > Danny HO

DATE CVE VULNERABILITY TITLE RISK
2010-06-02 CVE-2010-2132 Code Injection vulnerability in Danny HO OES 0.1
Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1 beta allow remote attackers to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) forum/admin.php and (2) plotgraph/index.php in admin/modules/modules/, and (3) admin_user/mod_admuser.php and (4) ogroup/mod_group.php in admin/modules/user_account/, different vectors than CVE-2007-1446.
network
low complexity
danny-ho CWE-94
7.5
2007-03-14 CVE-2007-1446 Code Injection vulnerability in Danny HO OES 0.1
Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1beta allow remote attackers to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) lib-account.inc.php, (2) lib-file.inc.php, (3) lib-group.inc.php, (4) lib-log.inc.php, (5) lib-mydb.inc.php, (6) lib-template-mod.inc.php, and (7) lib-themes.inc.php in includes/.
network
low complexity
danny-ho CWE-94
7.5