Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Nafsh

Pesquisador deCyberwh.org
#37282de 53,634
7.5CVSS total
Vulnerabilidades · 1
PT-2012-2177
7.5
2012-09-23
Dedecms · Dedecms · CVE-2011-5200
**Name of the Vulnerable Software and Affected Versions** DeDeCMS version 5.6 **Description** The issue concerns SQL injection vulnerabilities that allow remote attackers to execute arbitrary SQL commands. This can be achieved by manipulating the `id` parameter in the following API endpoints: "list.php", "members.php", or "book.php". **Recommendations** For DeDeCMS version 5.6, as a temporary workaround, consider restricting access to the `id` parameter in the affected API endpoints until a patch is available. Avoid using the `id` parameter in the "list.php", "members.php", and "book.php" endpoints to minimize the risk of exploitation.