Filtered by vendor Mariovaldez
Subscribe
Filtered by product Simple Text-file Login Script
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-5763 | 1 Mariovaldez | 1 Simple Text-file Login Script | 2024-02-04 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in slogin_lib.inc.php in Simple Text-File Login Script (SiTeFiLo) 1.0.6 allows remote attackers to execute arbitrary PHP code via a URL in the slogin_path parameter. | |||||
CVE-2008-5762 | 1 Mariovaldez | 1 Simple Text-file Login Script | 2024-02-04 | 5.0 MEDIUM | N/A |
Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for slog_users.txt. |