Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2010-1066
Disclosure Date: March 23, 2010 (last updated October 04, 2023)
AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for control/db_backup.php.
0
Attacker Value
Unknown
CVE-2009-3218
Disclosure Date: September 16, 2009 (last updated October 04, 2023)
SQL injection vulnerability in control/login.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
0
Attacker Value
Unknown
CVE-2009-3219
Disclosure Date: September 16, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the a parameter.
0