VendorsPhpeasycodepad_site_scripts3.6
Vulnerabilities

Phpeasycode Pad Site Scripts 3.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2009-1739
PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including administrative privileges, by setting the authuser cookie parameter to a valid username.
Published 2009-05-20 · Modified
7.51 PoCEPSS 0.028
CVE-2009-1941
PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for dbbackup.txt.
Published 2009-06-05 · Modified
5.01 PoCEPSS 0.023