Simplecustomer / Simple Customer
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2009-1637 | profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address and passwor… | MEDIUM | 6.4 | May 15, 2009 |
| CVE-2008-6332 | SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter. | HIGH | 7.5 | Feb 27, 2009 |
| CVE-2008-6326 | SQL injection vulnerability in login.php in Simple Customer as downloaded on 20081118 allows remote attackers to execute arbitrary SQL commands via the email p… | HIGH | 7.5 | Feb 27, 2009 |
| CVE-2008-6081 | SQL injection vulnerability in contact.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | HIGH | 7.5 | Feb 6, 2009 |
Showing 1 to 4 of 4 CVEs