Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Justqdjing

Pesquisador deSchool of Physical and Mathematical Sciences (SPMS), Nanyang Technological University (NTU), Singapore
#44661de 53,639
5.8CVSS total
Vulnerabilidades · 1
PT-2015-6425
5.8
2015-05-28
Phpwind · Phpwind · CVE-2015-4134
**Name of the Vulnerable Software and Affected Versions** phpwind version 8.7 **Description** The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the `url` parameter in the goto.php file. **Recommendations** For phpwind version 8.7, consider restricting access to the goto.php file or validating the `url` parameter to prevent redirects to unauthorized sites until a patch is available.