Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Zero X

#18817de 53,633
14.3CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2008-3100
4.3
2008-03-28
His · His Webshop · CVE-2008-1541
**Name of the Vulnerable Software and Affected Versions** HIS Webshop version 2.50 **Description** A directory traversal issue exists, allowing remote attackers to read arbitrary files. This is achieved by using a .. (dot dot) in the `t` parameter of the "cgi-bin/his-webshop.pl" endpoint. **Recommendations** For HIS Webshop version 2.50, consider restricting access to the cgi-bin/his-webshop.pl endpoint until a patch is available. As a temporary workaround, avoid using the `t` parameter in the affected endpoint to minimize the risk of exploitation.
PT-2007-7067
10
2007-11-30
K+B · K+B-Bestellsystem · CVE-2007-6176
**Name of the Vulnerable Software and Affected Versions** K+B-Bestellsystem (affected versions not specified) **Description** The issue allows remote attackers to execute arbitrary commands. This can be achieved by using shell metacharacters in the `domain` or `tld` parameters within a `check owner` action. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.