Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Lo$Er

#20430de 53,633
12.5CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2009-4636
5.0
2009-06-23
Gravy Media · Gravy Media Photo Host · CVE-2009-2184
**Name of the Vulnerable Software and Affected Versions** Gravy Media Photo Host version 1.0.8 **Description** The issue allows remote attackers to read arbitrary files due to an absolute path traversal vulnerability in the forcedownload.php file. This is achieved by using an encoded "/" (slash) in the `file` parameter. **Recommendations** For Gravy Media Photo Host version 1.0.8, consider restricting access to the forcedownload.php file until a patch is available. As a temporary workaround, avoid using the `file` parameter in the affected API endpoint until the issue is resolved.
PT-2008-4946
7.5
2008-08-10
Unknown · Africa Be Gone · CVE-2008-3570
**Name of the Vulnerable Software and Affected Versions** Africa Be Gone (ABG) version 1.0a **Description** The issue allows remote attackers to execute arbitrary PHP code via a URL in the `abg path` parameter in the index.php file. **Recommendations** For Africa Be Gone (ABG) version 1.0a, avoid using the `abg path` parameter in the index.php file until the issue is resolved. As a temporary workaround, consider restricting access to the index.php file to minimize the risk of exploitation.