Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Dar1In9S

#13799de 53,638
19.6CVSS total
Vulnerabilidades · 2
Crítica
2
PT-2023-28762
9.8
2023-09-26
Emlog Pro · Emlog Pro · CVE-2023-43291
**Name of the Vulnerable Software and Affected Versions** emlog pro versions 2.1.15 and earlier **Description** The issue allows a remote attacker to execute arbitrary code via the cache.php component due to deserialization of untrusted data. **Recommendations** For emlog pro versions 2.1.15 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-14805
9.8
2023-02-08
Thinkphp · Thinkphp · CVE-2022-45982
**Name of the Vulnerable Software and Affected Versions** thinkphp versions 6.0.0 through 6.0.13 thinkphp versions 6.1.0 through 6.1.1 **Description** The issue allows attackers to execute arbitrary code via a crafted payload, exploiting a deserialization vulnerability. This can be achieved by sending a malicious payload to be deserialized, potentially leading to remote code execution. **Recommendations** For thinkphp versions 6.0.0 through 6.0.13, update to a version outside of this range to mitigate the risk. For thinkphp versions 6.1.0 through 6.1.1, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting the use of the `unserialize()` function until a patch is available.