Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Shennan Wang

#19051de 53,638
14CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2008-6108
9.0
2008-11-05
U Mail · U-Mail Webmail Server · CVE-2008-4932
**Name of the Vulnerable Software and Affected Versions** U-Mail Webmail server version 4.91 **Description** The issue allows remote attackers to overwrite arbitrary files by providing an absolute pathname in the `path` parameter and arbitrary content in the `content` parameter in the webmail/modules/filesystem/edit.php file. This can be leveraged for code execution by writing to a file under the web document root. **Recommendations** For U-Mail Webmail server version 4.91, restrict access to the webmail/modules/filesystem/edit.php file to minimize the risk of exploitation. Avoid using the `path` and `content` parameters in this file until the issue is resolved.
PT-2008-2942
5.0
2008-03-17
Edior · Ediorcms · CVE-2008-1352
**Name of the Vulnerable Software and Affected Versions** EdiorCMS (ecms) version 3.0 **Description** A directory traversal issue exists in the search.php file, allowing remote attackers to read arbitrary files. This is achieved by including a .. (dot dot) in the ` SearchTemplate` parameter during a Title search. **Recommendations** For EdiorCMS (ecms) version 3.0, consider restricting access to the search.php file or limiting the ` SearchTemplate` parameter to prevent directory traversal attacks until a patch is available.