CVE-2007-2470
https://notcve.org/view.php?id=CVE-2007-2470
Multiple cross-site scripting (XSS) vulnerabilities in index.php in FileRun 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) module, or (3) section parameter. Múltiples vulnerabilidades de secuencia de comandos en sitios cruzados (XSS) en index.php en FileRun 1.0 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de los parámetros (1) page, (2) module, o (3) section. • http://pridels0.blogspot.com/2007/05/filerun-vuln.html http://secunia.com/advisories/25075 http://www.securityfocus.com/bid/23752 http://www.vupen.com/english/advisories/2007/1627 https://exchange.xforce.ibmcloud.com/vulnerabilities/34007 •
CVE-2007-2469
https://notcve.org/view.php?id=CVE-2007-2469
SQL injection vulnerability in index.php in FileRun 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter. Vulnerabilidad de inyección SQL en el FileRun 1.0 y versiones anteriores permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro fid. • http://pridels0.blogspot.com/2007/05/filerun-vuln.html http://secunia.com/advisories/25075 http://www.securityfocus.com/bid/23752 http://www.vupen.com/english/advisories/2007/1627 https://exchange.xforce.ibmcloud.com/vulnerabilities/34006 •