MidnightBSD

Advisories for cmsqlite

CVE-2010-2095 HIGH

SQL injection vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
cmsqlite cmsqlite 1.0
cmsqlite cmsqlite *
cmsqlite cmsqlite 1.1
CVE-2010-2096 HIGH

Directory traversal vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,

Products Affected

Vendor Product Version
cmsqlite cmsqlite 1.0
cmsqlite cmsqlite *
cmsqlite cmsqlite 1.1