Vulnerabilities > Dir2Web

DATE CVE VULNERABILITY TITLE RISK
2012-08-12 CVE-2012-4070 SQL Injection vulnerability in Dir2Web 3.0
SQL injection vulnerability in system/src/dispatcher.php in Dir2web 3.0 allows remote attackers to execute arbitrary SQL commands via the oid parameter in a homepage action to index.php.
network
low complexity
dir2web CWE-89
7.5
2012-08-12 CVE-2012-4069 Permissions, Privileges, and Access Controls vulnerability in Dir2Web 3.0
Dir2web 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database via a direct request for system/db/website.db.
network
low complexity
dir2web CWE-264
5.0