VendorsDiskosdiskos_cmsall versions
Vulnerabilities

Diskos Diskos CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2009-4798
Multiple SQL injection vulnerabilities in Diskos CMS 6.x allow remote attackers to execute arbitrary SQL commands via the (1) kat parameter to side.asp, and the (2) brugerid and (3) password fields to the administration login feature.
Published 2010-04-22 · Modified
7.51 PoCEPSS 0.010
CVE-2009-4799
Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) artikler_prod.mdb or (2) medlemmer.mdb.
Published 2010-04-22 · Modified
5.01 PoCEPSS 0.026