← Back

Dir2web

dir2web

Vendor: Dir2web • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dir2web
1Dir2web
Apr 29, 2026
Aug 12, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in system/src/dispatcher.php in Dir2web 3.0 allows remote attackers to execute arbitrary SQL commands via the oid parameter in a homepage action to index.php.
1Dir2web
1Dir2web
Apr 29, 2026
Aug 12, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Dir2web 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database via a direct request for system/db/website.db.