Vulnerabilities > Mpay24 Project

DATE CVE VULNERABILITY TITLE RISK
2014-09-12 CVE-2014-2009 Information Exposure vulnerability in Mpay24 Project Mpay24
The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive information via a direct request to api/curllog.log.
network
low complexity
mpay24-project CWE-200
5.0
2014-09-12 CVE-2014-2008 SQL Injection vulnerability in Mpay24 Project Mpay24
SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to execute arbitrary SQL commands via the TID parameter.
network
low complexity
mpay24-project CWE-89
7.5