Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Crazy_King

#35691de 53,640
7.5CVSS total
Vulnerabilidades · 1
PT-2007-2367
7.5
2007-02-14
Kv · Kvguestbook · CVE-2007-0926
Name of the Vulnerable Software and Affected Versions: KvGuestbook version 1.0 Beta Description: The issue allows remote attackers to gain administrative privileges, likely through modification of the `mysql['pass']` and `gbpass` variables in the `dologin` function. Recommendations: For KvGuestbook version 1.0 Beta, consider restricting access to the `dologin` function in guestbook.php until a patch is available. As a temporary workaround, avoid using the `mysql['pass']` and `gbpass` variables in the affected function to minimize the risk of exploitation.