Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2008-1900

Disclosure Date: April 22, 2008 (last updated October 04, 2023)
option_Update.asp in Carbon Communities 2.4 and earlier allows remote attackers to edit arbitrary member information via a modified ID field.
0
Attacker Value
Unknown

CVE-2007-0096

Disclosure Date: January 05, 2007 (last updated October 04, 2023)
CarbonCommunities stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for DataBase/Carbon2.4d.mdb.
0