Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Zhaohuan

#18073de 53,635
15CVSS total
Vulnerabilidades · 2
Alta
2
PT-2010-1440
7.5
2010-01-18
Comsenz · Discuzx · CVE-2009-4621
**Name of the Vulnerable Software and Affected Versions** Discuz! JiangHu Inn plugin versions 1.1 and earlier **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the `id` parameter in a show action to the "forummission.php" endpoint. **Recommendations** For versions 1.1 and earlier, consider restricting access to the "forummission.php" endpoint until a patch is available. As a temporary workaround, avoid using the `id` parameter in the show action to minimize the risk of exploitation.
PT-2009-5501
7.5
2009-09-15
Comsenz · Discuz! Crazy Star Plugin · CVE-2009-3185
**Name of the Vulnerable Software and Affected Versions** Discuz! Crazy Star plugin version 2.0 **Description** The issue allows remote authenticated users to execute arbitrary SQL commands. This is achieved via the `fmid` parameter in a "view" action in the `plugin.php` file of the Crazy Star plugin. **Recommendations** For version 2.0 of the Crazy Star plugin, avoid using the `fmid` parameter in the "view" action until a fix is available. As a temporary workaround, consider restricting access to the `plugin.php` file to minimize the risk of exploitation.