Vulnerabilities > Phpaddedit
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-04-02 | CVE-2008-6581 | Improper Authentication vulnerability in PHPaddedit 1.3 login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter. | 7.5 |
2009-02-27 | CVE-2008-6313 | Path Traversal vulnerability in PHPaddedit 1.3 Directory traversal vulnerability in addedit-render.php in phpAddEdit 1.3, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a URL in the editform parameter. | 6.8 |