Lucene search

K

Jemscripts Security Vulnerabilities

cve
cve

CVE-2006-2552

Jemscripts DownloadControl 1.0 allows remote attackers to obtain sensitive information via an invalid dcid parameter to dc.php, which leaks the pathname in an error message. NOTE: this was originally claimed to be SQL injection, but it is probably resultant from another issue in...

6.7AI Score

0.005EPSS

2006-05-24 01:02 AM
18
cve
cve

CVE-2006-2553

Cross-site scripting (XSS) vulnerability in Jemscripts DownloadControl 1.0 allows remote attackers to inject arbitrary HTML or web script via the dcid parameter to dc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. This issue.....

5.6AI Score

0.006EPSS

2006-05-24 01:02 AM
21