Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

D4V00D_Cr4Ck3R

Pesquisador devirangar security team
#35703de 53,779
7.5CVSS total
Vulnerabilidades · 1
PT-2009-2281
7.5
2009-05-21
Phpwebnews · Phpwebnews · CVE-2008-6812
Name of the Vulnerable Software and Affected Versions: phpWebNews version 0.2 MySQL Edition Description: The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `det` parameter in the bukutamu.php file. Recommendations: For phpWebNews version 0.2 MySQL Edition, consider restricting access to the bukutamu.php file until a patch is available. As a temporary workaround, avoid using the `det` parameter in the affected API endpoint.