📦

dreamweaver_ultradev

Vendor: macromedia

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 2.43% Exploit Prob.
Latest CVE CVE-2004-1893 Dec 31

Security Vulnerability Index

Page 1 / 1
5.0 CVSS

Dreamweaver MX, when "Using Driver On Testing Server" or "Using DSN on Testing Server" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp.

EPSS: 2.43%