Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Pehelwan

#14492de 53,635
18.6CVSS total
Vulnerabilidades · 2
Alta
1
Crítica
1
PT-2018-18014
8.8
2018-02-21
Danwin · Danwin · CVE-2018-7308
**Name of the Vulnerable Software and Affected Versions** DanWin hosting versions through 2018-02-11 **Description** A CSRF issue was found in `var/www/html/files.php` that allows arbitrary remote users to add, delete, or modify any files in any hosting account. **Recommendations** For versions through 2018-02-11, update to a version released after 2018-02-11 to resolve the issue. As a temporary workaround, consider restricting access to the `files.php` file to minimize the risk of exploitation.
PT-2018-17977
9.8
2018-02-19
Anchor · Anchor · CVE-2018-7251
**Name of the Vulnerable Software and Affected Versions** Anchor version 0.12.3 **Description** An issue was discovered in the `config/error.php` file. The error log is exposed at the "errors.log" URI and contains MySQL credentials if a MySQL error, such as "Too many connections", has occurred. **Recommendations** For Anchor version 0.12.3, consider restricting access to the "errors.log" URI to prevent exposure of MySQL credentials. As a temporary workaround, restrict access to the `config/error.php` file until a patch is available.