Vulnerabilities > Phpdirsubmit

DATE CVE VULNERABILITY TITLE RISK
2009-11-18 CVE-2009-3970 SQL Injection vulnerability in PHPdirsubmit PHP DIR Submit
SQL injection vulnerability in index.php in PHP Dir Submit (aka WebsiteSubmitter or Submitter Script) allows remote authenticated users to execute arbitrary SQL commands via the aid parameter in a showarticle action.
network
low complexity
phpdirsubmit CWE-89
6.5
2009-05-26 CVE-2009-1787 SQL Injection vulnerability in PHPdirsubmit PHP DIR Submit
Multiple SQL injection vulnerabilities in PHP Dir Submit (aka WebsiteSubmitter and Submitter Script) allow remote attackers to bypass authentication and gain administrative access via the (1) username and (2) password parameters.
network
low complexity
phpdirsubmit CWE-89
7.5