Lucene search

K

Post Affiliate Pro Security Vulnerabilities

cve
cve

CVE-2005-3909

SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the sortorder parameter.

8.8AI Score

0.008EPSS

2005-11-30 11:03 AM
25
cve
cve

CVE-2005-3910

merchants/index.php in Post Affiliate Pro 2.0.4 and earlier, with magic_quotes_gpc disabled, allows remote attackers to include arbitrary local files via the md parameter, possibly due to a directory traversal vulnerability.

7.2AI Score

0.002EPSS

2005-11-30 11:03 AM
21