Vulnerabilities > Digger Solutions

DATE CVE VULNERABILITY TITLE RISK
2007-01-09 CVE-2007-0116 Information Disclosure vulnerability in Intranet Open Source
Digger Solutions Intranet Open Source (IOS) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for data/intranet.mdb.
network
low complexity
digger-solutions
7.5
2005-12-31 CVE-2005-4822 SQL Injection vulnerability in Digger Solutions Intranet Open Source Project-Edit.ASP
SQL injection vulnerability in projects/project-edit.asp in Digger Solutions Intranet Open Source (IOS) version 2.7.2 allows remote attackers to execute arbitrary SQL commands via the project_id parameter.
network
low complexity
digger-solutions
7.5