Vulnerabilities > Frontaccounting > Frontaccounting > 2.3.1

DATE CVE VULNERABILITY TITLE RISK
2014-06-05 CVE-2014-3973 SQL Injection vulnerability in Frontaccounting
Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.3.21 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
frontaccounting CWE-89
7.5
2011-09-23 CVE-2011-3740 Information Exposure vulnerability in Frontaccounting 2.3.1
FrontAccounting 2.3.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by reporting/includes/fpdi/fpdi2tcpdf_bridge.php and certain other files.
network
low complexity
frontaccounting CWE-200
5.0