Page 4 of 17 results (0.004 seconds)

CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 1

SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization. Inyección SQL ha sido descubierta en adm_program/modules/dates/dates_function.php en Admidio 3.2.5. El parámetro POST dat_cat_id es concatenado en una consulta SQL sin ninguna entrada de validación/desinfección. • http://www.securityfocus.com/bid/97034 https://github.com/hamkovic/Admidio-3.2.5-SQLi • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 5.0EPSS: 1%CPEs: 1EXPL: 2

Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. Vulnerabilidad de salto de directorio en modules/download/get_file.php en Admidio v1.4.8 permite a atacantes remotos leer ficheros de su elección utilizando los caracteres .. (punto punto) en el parámetro "file". • https://www.exploit-db.com/exploits/5575 http://securityreason.com/securityalert/4625 http://www.securityfocus.com/bid/29127 https://exchange.xforce.ibmcloud.com/vulnerabilities/42304 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •