Vulnerabilities (CVE)

Filtered by vendor Dmxready Subscribe
Filtered by product Registration Manager
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-2238 1 Dmxready 1 Registration Manager 2023-12-10 6.8 MEDIUM N/A
Unrestricted file upload vulnerability in includes/shared_scripts/wysiwyg_editor/assetmanager/assetmanager.asp in DMXReady Registration Manager 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in assets/webblogmanager.
CVE-2009-1821 1 Dmxready 1 Registration Manager 2023-12-10 5.0 MEDIUM N/A
DMXReady Registration Manager 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for databases/webblogmanager.mdb.