Vulnerabilities > OI > Email Marketing System

DATE CVE VULNERABILITY TITLE RISK
2006-02-28 CVE-2006-0920 SQL Injection vulnerability in OI Email Marketing System 3.0
Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server's FTP password in cleartext on a Configuration web page, which allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the password.
local
low complexity
oi
1.7
2006-02-28 CVE-2006-0919 SQL-Injection vulnerability in OI Email Marketing System 3.0
SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.
network
low complexity
oi
7.5