Vulnerabilities (CVE)

Filtered by vendor Robs-projects Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-0328 1 Robs-projects 1 Digital Sales Ipn 2024-02-28 5.0 MEDIUM N/A
ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request for Database/Sales.mdb.
CVE-2008-6494 1 Robs-projects 1 Asp User Engine.net 2024-02-28 5.0 MEDIUM N/A
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for users.mdb.
CVE-2008-5601 1 Robs-projects 1 Asp User Engine 2024-02-28 5.0 MEDIUM N/A
User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users.mdb.