Vulnerabilities
Vulnerable Software
Dutchmonkey:  >> Dm Filemanager  Security Vulnerabilities
PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.
CVSS Score
6.8
EPSS Score
0.005
Published
2009-07-09
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to certain values.
CVSS Score
7.5
EPSS Score
0.018
Published
2009-06-09
Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.
CVSS Score
6.8
EPSS Score
0.009
Published
2009-05-20


Contact Us

Shodan ® - All rights reserved