Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Mstxq17

#13751de 53,639
19.6CVSS total
Vulnerabilidades · 2
Crítica
2
PT-2023-29770
9.8
2023-10-17
Unknown · Lylme Spage · CVE-2023-45951
**Name of the Vulnerable Software and Affected Versions** lylme spage version 1.7.0 **Description** The issue is related to a SQL injection vulnerability. This vulnerability can be exploited via the `$userip` parameter at `function.php`. **Recommendations** For lylme spage version 1.7.0, consider restricting access to the `$userip` parameter in the `function.php` file to minimize the risk of exploitation. As a temporary workaround, avoid using the `$userip` parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-29771
9.8
2023-10-17
Unknown · Lylme Spage · CVE-2023-45952
**Name of the Vulnerable Software and Affected Versions** lylme spage version 1.7.0 **Description** An arbitrary file upload vulnerability in the component `ajax link.php` of lylme spage allows attackers to execute arbitrary code via uploading a crafted file. **Recommendations** For lylme spage version 1.7.0, consider disabling the `ajax link.php` component until a patch is available to prevent arbitrary file uploads and subsequent code execution. Restrict access to this component to minimize the risk of exploitation.