Vulnerabilities (CVE)

Filtered by vendor Docmgr Subscribe
Filtered by product Docmgr
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-0687 1 Docmgr 1 Docmgr 2024-11-21 5.0 MEDIUM N/A
process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable.