Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Ismail Belkacim

#20351de 53,638
12.6CVSS total
Vulnerabilidades · 2
Média
2
PT-2017-11744
6.1
2017-07-08
Phpldapadmin · Phpldapadmin · CVE-2017-11107
**Name of the Vulnerable Software and Affected Versions** phpLDAPadmin versions prior to 1.2.3 **Description** The issue is related to XSS in the htdocs/entry chooser.php file, which can be exploited via the `form`, `element`, `rdn`, or `container` parameter. **Recommendations** For versions prior to 1.2.3, update to a version that contains a fix for this issue to prevent exploitation.
PT-2015-4220
6.5
2015-01-02
Pmb · Pmb · CVE-2014-9457
**Name of the Vulnerable Software and Affected Versions** PMB versions 4.1.3 and earlier **Description** The issue allows remote authenticated users to execute arbitrary SQL commands. This is achieved by exploiting the `id` parameter in the catalog.php file, which is vulnerable to SQL injection. **Recommendations** For PMB versions 4.1.3 and earlier, consider restricting access to the catalog.php file until a patch is available. As a temporary workaround, avoid using the `id` parameter in the catalog.php file to minimize the risk of exploitation.