DynPG CMS Local File Include and SQL Injection Vulnerabilities

  Bookmark
 and Share

DynPG CMS is a PHP-based content manager. The application is exposed to multiple issues. An attacker can exploit the local file include issue using directory traversal strings to view and execute arbitrary local files within the context of the web server process. DynPG CMS version 4.2.0 is affected.

Ref: http://www.dynpg.org/cms-freeware.php?read_article=225

10.50.43 - CVE: Not Available
Platform: Web Application - SQL Injection