CVE-2008-5935
Published Jan 21, 2009Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a d…
Vendor archive
2 CVEs tagged to vendor factosystem — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a d…
Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) th…