Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Robert Cooper

#17946de 53,638
15CVSS total
Vulnerabilidades · 2
Alta
2
PT-2014-8948
7.5
2014-12-08
Guruperl.Net · Awp Pro · CVE-2014-9345
**Name of the Vulnerable Software and Affected Versions** Guruperl.net Advertise With Pleasure! Professional (aka AWP PRO) versions 6.6 and earlier **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `group id` parameter in a "list zone" action to "cgi/client.cgi" API endpoint. **Recommendations** For versions 6.6 and earlier, avoid using the `group id` parameter in the "list zone" action to the "cgi/client.cgi" API endpoint until a fix is available. As a temporary workaround, consider restricting access to the "cgi/client.cgi" API endpoint to minimize the risk of exploitation.
PT-2012-6230
7.5
2012-11-26
Yabsoft · Yabsoft Advanced Image Hosting (Aih) Script · CVE-2012-6039
**Name of the Vulnerable Software and Affected Versions** YABSoft Advanced Image Hosting (AIH) Script version 2.3 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `gal` parameter in the view comments.php file. **Recommendations** For version 2.3, update to a version that fixes this issue to prevent remote attackers from executing arbitrary SQL commands.