Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ali Abdollahi

#13725of 53,633
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2018-14441
9.8
2018-12-20
Jco.Ir · Karma · CVE-2018-18399
**Name of the Vulnerable Software and Affected Versions** jco.ir KARMA version 6.0.0 **Description** A SQL injection issue exists in the `ContentPlaceHolder1 uxTitle` component in ArchiveNews.aspx, allowing a remote attacker to execute arbitrary SQL commands via the `id` parameter. **Recommendations** For jco.ir KARMA version 6.0.0, consider restricting access to the `id` parameter in the ArchiveNews.aspx page until a patch is available. As a temporary workaround, avoid using the `id` parameter in the affected page to minimize the risk of exploitation.
PT-2018-18082
9.8
2018-02-26
Asanhamayesh · Asanhamayesh Cms · CVE-2018-7463
**Name of the Vulnerable Software and Affected Versions** ASANHAMAYESH CMS version 3.4.6 **Description** A SQL injection issue exists in the files.php file of the "files" component, allowing a remote attacker to execute arbitrary SQL commands. The `id` parameter is vulnerable to this issue. **Recommendations** For ASANHAMAYESH CMS version 3.4.6, consider restricting access to the files.php file in the "files" component to minimize the risk of exploitation. Avoid using the `id` parameter in the affected component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.