Vulnerabilities > Phpaddedit

DATE CVE VULNERABILITY TITLE RISK
2009-04-02 CVE-2008-6581 Improper Authentication vulnerability in PHPaddedit 1.3
login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.
network
low complexity
phpaddedit CWE-287
7.5
2009-02-27 CVE-2008-6313 Path Traversal vulnerability in PHPaddedit 1.3
Directory traversal vulnerability in addedit-render.php in phpAddEdit 1.3, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a URL in the editform parameter.
network
phpaddedit CWE-22
6.8