Vulnerabilities > Turnkeyforms > Local Classifieds > High

DATE CVE VULNERABILITY TITLE RISK
2009-03-02 CVE-2008-6350 SQL Injection vulnerability in Turnkeyforms Local Classifieds
SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitrary SQL commands via the r parameter.
network
low complexity
turnkeyforms CWE-89
7.5
2009-02-26 CVE-2008-6302 Permissions, Privileges, and Access Controls vulnerability in Turnkeyforms Local Classifieds
TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/admin.php.
network
low complexity
turnkeyforms CWE-264
7.5