Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Zeq3Ul

Pesquisador deCWH Underground Hacking Team
#35434de 53,632
7.5CVSS total
Vulnerabilidades · 1
PT-2015-5679
7.5
2015-03-12
Php · Betster · CVE-2015-2237
**Name of the Vulnerable Software and Affected Versions** Betster (aka PHP Betoffice) version 1.0.4 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the `id` parameter to "showprofile.php" or "categoryedit.php", or the `username` parameter in a login to "index.php". **Recommendations** For Betster (aka PHP Betoffice) version 1.0.4, consider restricting access to the "showprofile.php", "categoryedit.php", and "index.php" scripts until a patch is available. As a temporary workaround, avoid using the `id` and `username` parameters in the affected API endpoints.