CVE-2008-5935
Published Jan 21, 2009Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a d…
Loading current evidence
Historical archive search
Search decades of CVEs by regex, severity, date, CWE, vendor/product tags, KEV, PoC, and other evidence.
Results
2 results · Sorted by Highest Buzz score first
Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a d…
Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) th…
Every filter state lives in the URL so you can bookmark, share, and crawl exact historical slices instead of a client-only search session.
Buzz order uses the latest all-time evidence snapshot, refreshed every two hours. Evidence-bearing CVEs rank first; records without a snapshot continue newest-first.