vendor:
MyDMS
by:
Unknown
7.5
CVSS
HIGH
Directory Traversal, SQL Injection
22, 89
CWE
Product Name: MyDMS
Affected Version From: Unknown
Affected Version To: 1.4.2 for SQL injection, 1.4.3 for directory traversal
Patch Exists: YES
Related CWE:
CPE: a:mydms_project:mydms
Platforms Tested: Unknown
Unknown
MyDMS Directory Traversal and SQL Injection Vulnerabilities
MyDMS is susceptible to a directory traversal vulnerability, allowing registered users to download arbitrary web server readable files, and an SQL injection vulnerability, allowing attackers to compromise the application and manipulate data or exploit vulnerabilities in the underlying database implementation.
Mitigation:
Upgrade to version 1.4.3 to fix the directory traversal vulnerability and version 1.4.2 to fix the SQL injection vulnerability.