Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Manich Koomsusi

#15372de 53,640
17.6CVSS total
Vulnerabilidades · 2
Alta
1
Crítica
1
PT-2019-13810
7.8
2019-10-14
Ubisoft · Uplay · CVE-2019-14737
**Name of the Vulnerable Software and Affected Versions** Uplay version 92.0.0.6280 **Description** The issue is related to insecure permissions in the software. **Recommendations** For version 92.0.0.6280, update to a newer version that addresses the insecure permissions issue.
PT-2017-19206
9.8
2017-09-07
WordPress · Watupro · CVE-2017-9834
**Name of the Vulnerable Software and Affected Versions** WatuPRO plugin versions prior to 5.5.3.7 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the `watupro questions` parameter in a `watupro submit` action to the "/wp-admin/admin-ajax.php" API endpoint. **Recommendations** For versions prior to 5.5.3.7, update to version 5.5.3.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/wp-admin/admin-ajax.php" API endpoint to minimize the risk of exploitation. Avoid using the `watupro questions` parameter in the affected API endpoint until the issue is resolved.