Vulnerabilities > Phpeasycode

DATE CVE VULNERABILITY TITLE RISK
2009-06-05 CVE-2009-1941 Permissions, Privileges, and Access Controls vulnerability in PHPeasycode PAD Site Scripts 3.6
PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for dbbackup.txt.
network
low complexity
phpeasycode CWE-264
5.0
2009-05-20 CVE-2009-1739 Improper Input Validation vulnerability in PHPeasycode PAD Site Scripts 3.6
PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including administrative privileges, by setting the authuser cookie parameter to a valid username.
network
low complexity
phpeasycode CWE-20
7.5