Vulnerabilities (CVE)

Filtered by vendor Phpdirector Subscribe
Filtered by product Phpdirector
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-3529 1 Phpdirector 1 Phpdirector 2024-02-04 7.8 HIGH N/A
videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of the id[] parameter, which reveals the path in an error message.
CVE-2007-3530 1 Phpdirector 1 Phpdirector 2024-02-04 7.2 HIGH N/A
PHPDirector 0.21 and earlier stores the admin account name and password in config.php, which allows local users to gain privileges by reading this file.