Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Nigh7F411

#18853de 53,640
14.3CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2008-6213
4.3
2008-11-13
Modernbill · Modernbill · CVE-2008-5059
**Name of the Vulnerable Software and Affected Versions** ModernBill versions 4.4 and earlier **Description** The issue concerns a cross-site scripting (XSS) vulnerability. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a Javascript event in the `new language` parameter in a login action. **Recommendations** For ModernBill versions 4.4 and earlier, update to a version later than 4.4 to resolve the issue. As a temporary workaround, consider restricting access to the login action or disabling the use of the `new language` parameter until a patch is available.
PT-2008-6214
10
2008-11-13
Modernbill · Modernbill · CVE-2008-5060
Multiple PHP remote file inclusion vulnerabilities in ModernBill 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) export batch.inc.php, (2) run auto suspend.cron.php, and (3) send email cache.php in include/scripts/; (4) include/misc/mod 2checkout/2checkout return.inc.php; and (5) include/html/nettools.popup.php, different vectors than CVE-2006-4034 and CVE-2005-1054.