Vulnerabilities > Digger Solutions
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2007-01-09 | CVE-2007-0116 | Information Disclosure vulnerability in Intranet Open Source Digger Solutions Intranet Open Source (IOS) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for data/intranet.mdb. | 7.5 |
2005-12-31 | CVE-2005-4822 | SQL Injection vulnerability in Digger Solutions Intranet Open Source Project-Edit.ASP SQL injection vulnerability in projects/project-edit.asp in Digger Solutions Intranet Open Source (IOS) version 2.7.2 allows remote attackers to execute arbitrary SQL commands via the project_id parameter. | 7.5 |