Vulnerabilities
Vulnerable Software
Energine:  >> Energine  Security Vulnerabilities
Energine 2.3.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by core/framework/SimpleBuilder.class.php and certain other files.
CVSS Score
5.0
EPSS Score
0.003
Published
2011-09-23
SQL injection vulnerability in index.php in Energine, possibly 2.3.8 and earlier, allows remote attackers to execute arbitrary SQL commands via the NRGNSID cookie.
CVSS Score
7.5
EPSS Score
0.004
Published
2010-11-05


Contact Us

Shodan ® - All rights reserved