Vulnerabilities > Merlix > Teamworx Server

DATE CVE VULNERABILITY TITLE RISK
2008-12-16 CVE-2008-5600 Permissions, Privileges, and Access Controls vulnerability in Merlix Teamworx Server NIL
Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for teamworx.mdb.
network
low complexity
merlix CWE-264
5.0
2008-12-16 CVE-2008-5599 SQL Injection vulnerability in Merlix Teamworx Server NIL
SQL injection vulnerability in default.asp in Merlix Teamworx Server allows remote attackers to execute arbitrary SQL commands via the password parameter (aka passwd field) in a login action.
network
low complexity
merlix CWE-89
7.5