Vulnerabilities > Esyndicat > Esyndicat Directory

DATE CVE VULNERABILITY TITLE RISK
2007-07-17 CVE-2007-3811 SQL Injection vulnerability in Esyndicat Directory 1.6
Multiple SQL injection vulnerabilities in eSyndiCat allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php or (2) the name parameter to page.php.
network
low complexity
esyndicat
7.5
2006-05-24 CVE-2006-2578 Remote Security vulnerability in Esyndicat Directory 1.2
admin/cron.php in eSyndicat Directory 1.2, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files and possibly execute arbitrary PHP code via a null-terminated value in the path_to_config parameter.
network
high complexity
esyndicat
5.1