Phpeasycode Pad Site Scripts vulnerabilities
2 known vulnerabilities affecting phpeasycode/pad_site_scripts.
Total CVEs
2
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2009-1739P3HIGHCVSS 7.5PoCv3.62009-05-20
CVE-2009-1739 [HIGH] CWE-20 CVE-2009-1739: PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other u
PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including administrative privileges, by setting the authuser cookie parameter to a valid username.
nvd
CVE-2009-1941P4MEDIUMCVSS 5.0PoCv3.62009-06-05
CVE-2009-1941 [MEDIUM] CWE-264 CVE-2009-1941: PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient acce
PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for dbbackup.txt.
nvd