Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

The_Huligun

#19972de 56,330
14.3CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2008-2090
6.8
2008-01-25
Slaed · Slaed Cms · CVE-2008-0458
**Name of the Vulnerable Software and Affected Versions** SLAED CMS version 2.5 Lite **Description** A directory traversal issue exists in the function/sources.php file of SLAED CMS, allowing remote attackers to include and execute arbitrary local files. This is achieved by providing a .. (dot dot) in the `newlang` parameter to the "index.php" endpoint. **Recommendations** For SLAED CMS version 2.5 Lite, consider restricting access to the `newlang` parameter in the "index.php" endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2008-2056
7.5
2008-01-23
Mooseguy · Mooseguy Blog System · CVE-2008-0424
**Name of the Vulnerable Software and Affected Versions** Mooseguy Blog System (MGBS) version 1.0 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `month` parameter in the blog.php file. **Recommendations** For Mooseguy Blog System (MGBS) version 1.0, consider restricting access to the `month` parameter in the blog.php file to minimize the risk of exploitation.