CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dotnetindex 1Professional Download Assistant Apr 23, 2026 Dec 15, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for database/download...Show more |
1Dotnetindex 1Professional Download Assistant Apr 23, 2026 Dec 15, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka p...Show more |