Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Passtion

#21937de 53,633
10.8CVSS total
Vulnerabilidades · 2
Média
2
PT-2017-11644
4.3
2017-07-06
Finecms · Finecms · CVE-2017-10967
**Name of the Vulnerable Software and Affected Versions** FineCMS versions prior to 2017-07-06 **Description** The issue allows for XSS in the `key name`, `key value`, and `meaning` parameters within the application/core/controller/config.php file. **Recommendations** For versions prior to 2017-07-06, update to a version released after 2017-07-06 to resolve the issue.
PT-2017-11650
6.5
2017-07-06
Finecms · Finecms · CVE-2017-10973
**Name of the Vulnerable Software and Affected Versions** FineCMS versions prior to 2017-07-06 **Description** The issue is related to Server-Side Request Forgery (SSRF) in the application/lib/ajax/get image data.php file. It occurs when requests are made for non-image files with a modified HTTP Host header. **Recommendations** For versions prior to 2017-07-06, update to a version released after 2017-07-06 to resolve the issue.