Vulnerabilities (CVE)

Filtered by vendor Baalsystems Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-2144 1 Baalsystems 1 Baal Smart Forms 2024-01-25 7.5 HIGH N/A
Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php.
CVE-2010-0611 1 Baalsystems 1 Baal Systems 2023-12-10 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.