Vulnerabilities > Dazzlindonna

DATE CVE VULNERABILITY TITLE RISK
2008-12-15 CVE-2008-5560 Permissions, Privileges, and Access Controls vulnerability in Dazzlindonna Postecards
PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for postcards.mdb.
network
low complexity
dazzlindonna CWE-264
5.0
2008-12-15 CVE-2008-5559 SQL Injection vulnerability in Dazzlindonna Postecards
SQL injection vulnerability in sendcard.cfm in PostEcards allows remote attackers to execute arbitrary SQL commands via the cid parameter.
network
low complexity
dazzlindonna CWE-89
7.5