XLineSoft PHPRunner 4.2

CPE Details

XLineSoft PHPRunner 4.2
4.2
2024-04-29
10h55 +00:00
2024-04-29
10h55 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:xlinesoft:phprunner:4.2:*:*:*:*:*:*:*

Informations

Vendor

xlinesoft

Product

phprunner

Version

4.2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2009-0963 2009-03-19 09h00 +00:00 Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserView_list.php, (2) orders_list.php, (3) users_list.php, and (4) Administrator_list.php.
7.5
CVE-2009-0964 2009-03-19 09h00 +00:00 UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication.
7.5
High