Skip to main content

Vendor/product archive

asp-dev / xm_events_diary CVEs

Beta · best-effort

3 CVEs tagged to asp-dev / xm_events_diary0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2008-5925

Published Jan 21, 2009

ASP-DEv XM Events Diary stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5924

Published Jan 21, 2009

SQL injection vulnerability in diary_viewC.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5923

Published Jan 21, 2009

SQL injection vulnerability in default.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands the cat parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1