Vulnerabilities (CVE)

Filtered by vendor Dsportal Subscribe
Filtered by product Dslogin
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-1238 1 Dsportal 1 Dslogin 2024-02-04 5.1 MEDIUM N/A
SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the $log_userid variable in (1) index.php and (2) admin/index.php.