Vulnerabilities > Profilecms
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2007-11-20 | CVE-2007-6058 | SQL Injection vulnerability in Profilecms Multiple SQL injection vulnerabilities in index.php in ProfileCMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) codes action in the profile-codes module, (2) videos action in the video-codes module, or (3) games action in the arcade-games module. | 7.5 |
2007-10-30 | CVE-2007-5720 | Code Injection vulnerability in Profilecms 1.0 Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving creation of a profile. | 6.8 |