Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Anthony Dubuissez

Pesquisador deWebera
#41451de 53,638
6.5CVSS total
Vulnerabilidades · 1
PT-2014-2718
6.5
2014-03-11
Php · Simple Php Agenda · CVE-2013-3961
**Name of the Vulnerable Software and Affected Versions** Simple PHP Agenda versions prior to 2.2.9 **Description** The issue allows remote authenticated users to execute arbitrary SQL commands. This is achieved via the `eventid` parameter in the "edit event.php" file. **Recommendations** For versions prior to 2.2.9, update to version 2.2.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the "edit event.php" file or avoiding the use of the `eventid` parameter until the issue is resolved.