Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Srsec

#15351de 53,630
17.6CVSS total
Vulnerabilidades · 2
Alta
1
Crítica
1
PT-2023-12116
7.8
2023-05-08
Mblog · Mblog · CVE-2021-27280
**Name of the Vulnerable Software and Affected Versions** mblog version 3.5.0 **Description** The issue allows attackers to execute arbitrary code via a crafted theme when it gets selected. This is due to an OS Command injection vulnerability. **Recommendations** For mblog version 3.5.0, update to a newer version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2019-12855
9.8
2019-06-02
Douphp · Douphp · CVE-2019-12564
**Name of the Vulnerable Software and Affected Versions** DouPHP version 1.5 Release 20190516 **Description** The issue allows remote attackers to view the database backup file through a brute-force guessing approach for filenames in the format data/backup/DyyyymmddThhmmss.sql. **Recommendations** For DouPHP version 1.5 Release 20190516, consider restricting access to the backup files in the data/backup directory to prevent unauthorized viewing.