Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Post Affiliate Pro Subscribe
Filtered by product Post Affiliate Pro
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-3909 1 Post Affiliate Pro 1 Post Affiliate Pro 2017-07-19 7.5 HIGH N/A
SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the sortorder parameter.
CVE-2005-3910 1 Post Affiliate Pro 1 Post Affiliate Pro 2009-10-08 5.0 MEDIUM N/A
merchants/index.php in Post Affiliate Pro 2.0.4 and earlier, with magic_quotes_gpc disabled, allows remote attackers to include arbitrary local files via the md parameter, possibly due to a directory traversal vulnerability.