Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

The_Huligun

#18740de 53,635
14.3CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2008-2090
6.8
2008-01-25
Slaed · Slaed Cms · CVE-2008-0458
**Name of the Vulnerable Software and Affected Versions** SLAED CMS version 2.5 Lite **Description** A directory traversal issue exists in the function/sources.php file of SLAED CMS, allowing remote attackers to include and execute arbitrary local files. This is achieved by providing a .. (dot dot) in the `newlang` parameter to the "index.php" endpoint. **Recommendations** For SLAED CMS version 2.5 Lite, consider restricting access to the `newlang` parameter in the "index.php" endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2008-2056
7.5
2008-01-23
Mooseguy · Mooseguy Blog System · CVE-2008-0424
**Name of the Vulnerable Software and Affected Versions** Mooseguy Blog System (MGBS) version 1.0 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `month` parameter in the blog.php file. **Recommendations** For Mooseguy Blog System (MGBS) version 1.0, consider restricting access to the `month` parameter in the blog.php file to minimize the risk of exploitation.