Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

!-Bugjack-!

#21167de 53,640
11.8CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2009-2802
7.5
2009-01-09
Ezpack · Ezpack · CVE-2009-0104
**Name of the Vulnerable Software and Affected Versions** EZpack version 4.2b2 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `qType` parameter in a "webboard prog" action. **Recommendations** For EZpack version 4.2b2, avoid using the `qType` parameter in the "webboard prog" action until a fix is available. Consider restricting access to the vulnerable `index.php` file to minimize the risk of exploitation.
PT-2009-2803
4.3
2009-01-09
Ezpack · Ezpack · CVE-2009-0105
**Name of the Vulnerable Software and Affected Versions** EZpack version 4.2b2 **Description** A cross-site scripting issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the `mfdf` parameter in a 'prog' action in the index.php file. **Recommendations** For EZpack version 4.2b2, consider restricting access to the `mfdf` parameter in the index.php file to minimize the risk of exploitation. Avoid using the `mfdf` parameter in the affected API endpoint until the issue is resolved.