Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

A.1.M

#37268de 53,632
7.5CVSS total
Vulnerabilidades · 1
PT-2005-4432
7.5
2005-11-18
Phpwebthings · Phpwebthings · CVE-2005-3676
**Name of the Vulnerable Software and Affected Versions** PhpWebThings version 1.4.4 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `file` parameter in the "download.php" API endpoint. **Recommendations** For PhpWebThings version 1.4.4, consider restricting access to the `download.php` endpoint until a patch is available, and avoid using the `file` parameter to minimize the risk of exploitation.