Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

B0Rizq

#21573de 53,632
11.1CVSS total
Vulnerabilidades · 2
Média
2
PT-2006-6239
6.8
2006-10-26
Phplist · Phplist · CVE-2006-5524
**Name of the Vulnerable Software and Affected Versions** phplist version 2.10.2 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the `p` parameter in the "index.php" file. **Recommendations** For phplist version 2.10.2, consider restricting access to the `p` parameter in the "index.php" file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2006-6218
4.3
2006-10-25
Simple Machines · Simple Machines Forum · CVE-2006-5503
**Name of the Vulnerable Software and Affected Versions** Simple Machines Forum (SMF) version 1.1 RC2 **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the `action` parameter in the "index.php" file. **Recommendations** For Simple Machines Forum (SMF) version 1.1 RC2, avoid using the `action` parameter in the index.php file until a fix is available. As a temporary workaround, consider restricting access to the index.php file to minimize the risk of exploitation.