Vulnerabilities > Superfreaker Studios > Upublisher > 1.0

DATE CVE VULNERABILITY TITLE RISK
2006-12-08 CVE-2006-6399 SQL-Injection vulnerability in Superfreaker Studios Upublisher 1.0
SQL injection vulnerability in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the Username parameter in login.asp.
network
low complexity
superfreaker-studios
7.5
2006-12-08 CVE-2006-6398 SQL-Injection vulnerability in Superfreaker Studios Upublisher 1.0
Multiple SQL injection vulnerabilities in Superfreaker Studios UPublisher 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors in (a) sendarticle.asp and (b) printarticle.asp, and the ID parameter to (c) index.asp and (d) preferences.asp, different vectors than CVE-2006-5888.
network
low complexity
superfreaker-studios
7.5
2006-11-14 CVE-2006-5888 SQL-Injection vulnerability in Superfreaker Studios Upublisher 1.0
SQL injection vulnerability in viewarticle.asp in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
network
low complexity
superfreaker-studios
7.5