Vulnerabilities > Kwsphp > Kwsphp > 1.3.456

DATE CVE VULNERABILITY TITLE RISK
2009-02-20 CVE-2008-6201 Path Traversal vulnerability in Kwsphp 1.3.456
Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allows remote attackers to execute arbitrary commands via the action parameter.
network
kwsphp CWE-22
6.8
2009-02-20 CVE-2008-6197 SQL Injection vulnerability in Kwsphp Galerie Module
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arbitrary SQL commands via the id_gal parameter in a gal action.
network
low complexity
kwsphp CWE-89
7.5