Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

41.W4R10R

#20469of 53,633
12.5Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2010-3312
5.0
2010-04-30
Help Center Live · Help Center Live · CVE-2010-1652
**Name of the Vulnerable Software and Affected Versions** Help Center Live versions 2.0.6 through 2.1.7 **Description** The issue allows remote attackers to read arbitrary files and possibly have other impacts via a .. (dot dot) in the `file` parameter to "module.php". **Recommendations** For versions 2.0.6 and 2.1.7, consider restricting access to the module.php file until a fix is available. As a temporary workaround, avoid using the `file` parameter in the module.php file to minimize the risk of exploitation.
PT-2010-3320
7.5
2010-04-30
Clscript · Clscript Classifieds Script · CVE-2010-1660
**Name of the Vulnerable Software and Affected Versions** CLScript Classifieds Script (affected versions not specified) **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `hpId` parameter in the "help-details.php" file. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.