Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Cru3L.B0Y

#18057de 53,638
15CVSS total
Vulnerabilidades · 2
Alta
2
PT-2011-1725
7.5
2011-03-23
Unknown · Pre Online Tests Generator Pro · CVE-2010-4776
**Name of the Vulnerable Software and Affected Versions** Pre Online Tests Generator Pro (affected versions not specified) **Description** The issue allows remote attackers to execute arbitrary SQL commands via the `tid2` parameter in the `takefreestart.php` file. This can lead to unauthorized access and manipulation of database content. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2008-5458
7.5
2008-09-22
Unknown · Zanfi Cms Lite · CVE-2008-4159
**Name of the Vulnerable Software and Affected Versions** Jaw Portal (affected versions not specified) Zanfi CMS lite (affected versions not specified) **Description** The issue allows remote attackers to execute arbitrary SQL commands via the `pageid` parameter in the "index.php" file. This can be exploited by sending a malicious request to the `/index.php` endpoint. **Recommendations** For Jaw Portal, update the index.php file to properly sanitize the `pageid` parameter to prevent SQL injection. For Zanfi CMS lite, update the index.php file to properly sanitize the `pageid` parameter to prevent SQL injection. As a temporary workaround, consider restricting access to the index.php file until a patch is available.