Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

壱

#21086de 53,779
11.8CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2015-5994
7.5
2015-05-25
Hajime Fujimoto · Mt-Phpincgi.Php · CVE-2015-2945
**Name of the Vulnerable Software and Affected Versions** mt-phpincgi.php in Hajime Fujimoto mt-phpincgi versions prior to 2015-05-15 **Description** The issue allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted request. This has been exploited in the wild in May 2015. **Recommendations** For versions prior to 2015-05-15, update to a version released after 2015-05-15 to resolve the issue. As a temporary workaround, consider restricting access to the mt-phpincgi.php file to minimize the risk of exploitation.
PT-2012-1261
4.3
2012-01-04
Movable Type · Movable Type Mailform Plugin · CVE-2007-6751
**Name of the Vulnerable Software and Affected Versions** Movable Type MailForm plugin versions prior to 1.20 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML. **Recommendations** For Movable Type MailForm plugin versions prior to 1.20, update to version 1.20 or later to resolve the issue.