Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alessio Santoru

#15872of 53,632
17Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2022-19372
7.2
2022-09-26
WordPress · Ninja Forms Contact Form · CVE-2022-2903
**Name of the Vulnerable Software and Affected Versions** Ninja Forms Contact Form WordPress plugin versions prior to 3.6.13 **Description** The issue arises from the unserialization of the content of an imported file, potentially leading to PHP object injections when an admin imports a malicious file and a suitable gadget chain is present on the blog. This could occur intentionally or unintentionally. **Recommendations** For versions prior to 3.6.13, update to version 3.6.13 or later to resolve the issue. As a temporary workaround, consider restricting file imports to trusted sources and avoiding the import of files from unverified locations.
PT-2018-6543
9.8
2018-02-06
Acme · Thttpd · CVE-2017-17663
Name of the Vulnerable Software and Affected Versions: mini httpd versions prior to 1.28 thttpd versions prior to 2.28 Description: The issue is related to a buffer overflow in the htpasswd implementation, which can be exploited remotely to perform code execution. Recommendations: For mini httpd versions prior to 1.28, update to version 1.28 or later. For thttpd versions prior to 2.28, update to version 2.28 or later.