Vulnerabilities (CVE)

Filtered by vendor Easyweb Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-2047 1 Easyweb 1 Easyweb Filemanager 2024-02-28 5.0 MEDIUM N/A
Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter.
CVE-2004-1668 1 Easyweb 1 Factory Subjects Module 2024-02-28 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in index.php in Subjects 2.0 Postnuke module allow remote attackers to execute arbitrary SQL commands via the (1) pageid, (2) subid, or (3) catid parameters.