Vulnerabilities > Solis > Gnuteca > 3.8

DATE CVE VULNERABILITY TITLE RISK
2020-05-09 CVE-2020-12766 SQL Injection vulnerability in Solis Gnuteca 3.8
Gnuteca 3.8 allows action=main:search:simpleSearch SQL Injection via the exemplaryStatusId parameter.
network
low complexity
solis CWE-89
7.5
2020-05-09 CVE-2020-12764 Path Traversal vulnerability in Solis Gnuteca 3.8
Gnuteca 3.8 allows file.php?folder=/&file= Directory Traversal.
network
low complexity
solis CWE-22
5.0