Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Johan Cwiklinski

#37224de 53,635
7.5CVSS total
Vulnerabilidades · 1
PT-2012-3960
7.5
2012-05-21
Galette · Galette · CVE-2012-2338
**Name of the Vulnerable Software and Affected Versions** Galette versions 0.63 through 0.63.3 Galette version 0.64rc1 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `id adh` parameter to "picture.php". **Recommendations** For Galette versions 0.63 through 0.63.3, and version 0.64rc1, avoid using the `id adh` parameter in the "picture.php" endpoint until the issue is resolved.