Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

壱

#21162of 53,633
11.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2015-5994
7.5
2015-05-25
Hajime Fujimoto · Mt-Phpincgi.Php · CVE-2015-2945
**Name of the Vulnerable Software and Affected Versions** mt-phpincgi.php in Hajime Fujimoto mt-phpincgi versions prior to 2015-05-15 **Description** The issue allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted request. This has been exploited in the wild in May 2015. **Recommendations** For versions prior to 2015-05-15, update to a version released after 2015-05-15 to resolve the issue. As a temporary workaround, consider restricting access to the mt-phpincgi.php file to minimize the risk of exploitation.
PT-2012-1261
4.3
2012-01-04
Movable Type · Movable Type Mailform Plugin · CVE-2007-6751
**Name of the Vulnerable Software and Affected Versions** Movable Type MailForm plugin versions prior to 1.20 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML. **Recommendations** For Movable Type MailForm plugin versions prior to 1.20, update to version 1.20 or later to resolve the issue.