Vulnerabilities > Profilecms

DATE CVE VULNERABILITY TITLE RISK
2007-11-20 CVE-2007-6058 SQL Injection vulnerability in Profilecms
Multiple SQL injection vulnerabilities in index.php in ProfileCMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) codes action in the profile-codes module, (2) videos action in the video-codes module, or (3) games action in the arcade-games module.
network
low complexity
profilecms CWE-89
7.5
2007-10-30 CVE-2007-5720 Code Injection vulnerability in Profilecms 1.0
Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving creation of a profile.
network
profilecms CWE-94
6.8