MidnightBSD

Advisories for thorsten_korner

CVE-2002-2167 MEDIUM

Directory traversal vulnerability in function_foot_1.inc.php for Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences terminated by a null character in the $designNo variable, which is part of an "include" function call.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
thorsten_korner 123tkshop 0.3
thorsten_korner 123tkshop 0.2
CVE-2002-2168 HIGH

SQL injection vulnerability in Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to execute arbitrary SQL queries via various programs including function_describe_item1.inc.php.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
thorsten_korner 123tkshop 0.3
thorsten_korner 123tkshop 0.2