← Back

Web Hosting Directory

web_hosting_directory

Vendor: Turnkeyforms • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Turnkeyforms
1Web Hosting Directory
Apr 23, 2026
Aug 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to execute arbitrary SQL commands via the password field.
1Turnkeyforms
1Web Hosting Directory
Apr 23, 2026
Aug 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain a database backup via a direct request to admin/backup/db.
1Turnkeyforms
1Web Hosting Directory
Apr 23, 2026
Aug 12, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie to 1 or (2) gain privileges as another user by setting the logged cooki...Show more
TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie to 1 or (2) gain privileges as another user by setting the logged cookie to the target username.Show less