Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Audun Larsen

#21143of 53,632
11.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2008-1747
4.3
2008-01-04
Phpwebsite · Phpwebsite · CVE-2008-0092
**Name of the Vulnerable Software and Affected Versions** phpWebSite version 1.4.0 **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the `search` parameter in the search module of index.php. **Recommendations** For phpWebSite version 1.4.0, consider restricting access to the search module until a fix is available, or avoid using the `search` parameter in the affected API endpoint.
PT-2006-1771
7.5
2006-02-15
Php · Php Classifieds · CVE-2006-0719
**Name of the Vulnerable Software and Affected Versions** PHP Classifieds versions 6.18 through 6.20 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `username` and `password` parameters in the member login.php file. **Recommendations** For PHP Classifieds versions 6.18 through 6.20, consider restricting access to the member login.php file until a patch is available. As a temporary workaround, avoid using the `username` and `password` parameters in the affected file to minimize the risk of exploitation.