Vulnerabilities > Pdfdirectory

DATE CVE VULNERABILITY TITLE RISK
2006-01-19 CVE-2006-0314 SQL-Injection vulnerability in pdfdirectory
PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users' passwords by direct queries to the database, possibly via one of the SQL injection vulnerabilities.
network
low complexity
pdfdirectory
7.5
2006-01-19 CVE-2006-0313 SQL Injection vulnerability in PDFDirectory
Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (3) user.php, (4) uploadfrm.php, (5) title.php, (6) team.php, (7) stats.php, (8) page.php, (9) org.php, (10) member.php, (11) index.php, (12) group.php, or (13) anniv.php.
network
low complexity
pdfdirectory
7.5