Lucene search

K

Dutchmonkey Security Vulnerabilities

cve
cve

CVE-2009-1741

Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.

8.8AI Score

0.001EPSS

2009-05-20 07:30 PM
19
cve
cve

CVE-2009-2025

admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to certain values.

7.3AI Score

0.019EPSS

2009-06-09 07:30 PM
27
cve
cve

CVE-2009-2396

PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.

7.8AI Score

0.027EPSS

2009-07-09 04:30 PM
22
cve
cve

CVE-2009-2399

PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.

7.8AI Score

0.014EPSS

2009-07-09 04:30 PM
21