Skip to main content

Vendor archive

xlinesoft CVEs

Beta · best-effort

7 CVEs tagged to vendor xlinesoft0 Critical, 3 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2009-0964

Published Mar 19, 2009

UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged wi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0963

Published Mar 19, 2009

Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserVi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5956

Published Nov 17, 2006

XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-2057

Published Dec 31, 2004

SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2058

Published Dec 31, 2004

ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2059

Published Dec 31, 2004

Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2060

Published Dec 31, 2004

ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, wh…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1