Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Bill Heinbockel

Researcher fromThe MITRE Corporation
#17938of 53,633
15Total CVSS
Vulnerabilities · 2
High
2
PT-2007-1251
7.5
2007-02-07
Btitracker · Btitracker · CVE-2006-6972
**Name of the Vulnerable Software and Affected Versions** BtitTracker versions 1.3.2 and earlier **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `by` and `order` parameters in the torrents.php file. However, it is not clear whether this issue is exploitable. **Recommendations** For BtitTracker versions 1.3.2 and earlier, consider restricting access to the torrents.php file until a patch is available. As a temporary workaround, avoid using the `by` and `order` parameters in the affected file to minimize the risk of exploitation.
PT-2006-6188
7.5
2006-10-24
Softerra · Softerra Php Developer Library · CVE-2006-5473
**Name of the Vulnerable Software and Affected Versions** Softerra PHP Developer Library versions 1.5.3 and earlier **Description** A remote file inclusion issue allows remote attackers to execute arbitrary PHP code via the `lib dir` parameter. **Recommendations** For Softerra PHP Developer Library versions 1.5.3 and earlier, consider restricting access to the `lib dir` parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.