Vulnerabilities > Savas Place > Savas Link Manager > 2.0

DATE CVE VULNERABILITY TITLE RISK
2008-04-02 CVE-2008-1653 Path Traversal vulnerability in Savas Place Savas Link Manager 2.0
Directory traversal vulnerability in index.php in Sava's Link Manager 2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the q parameter.
6.8
2008-04-02 CVE-2008-1644 SQL Injection vulnerability in Savas Place Savas Link Manager 2.0
SQL injection vulnerability in viewlinks.php in Sava's Link Manager 2.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.
network
low complexity
savas-place CWE-89
7.5