Vulnerabilities > Infireal

DATE CVE VULNERABILITY TITLE RISK
2009-08-12 CVE-2008-6956 Code Injection vulnerability in Infireal Mxcamarchive 2.2
Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via the description parameter, which is executed by invocation of index.php.
network
low complexity
infireal CWE-94
6.5
2009-08-12 CVE-2008-6955 Information Exposure vulnerability in Infireal Mxcamarchive 2.2
mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a direct request for archive/config.ini.
network
low complexity
infireal CWE-200
7.5
2009-02-24 CVE-2008-6263 SQL Injection vulnerability in Infireal Saturncms
SQL injection vulnerability in lib/user/t_user.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the username parameter to the _userLoggedIn function.
network
low complexity
infireal CWE-89
7.5
2009-02-24 CVE-2008-6262 SQL Injection vulnerability in Infireal Saturncms
SQL injection vulnerability in lib/url/meta_url.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the URL to the translate function.
network
low complexity
infireal CWE-89
7.5