Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Cru3L.B0Y

#18037of 53,633
15Total CVSS
Vulnerabilities · 2
High
2
PT-2011-1725
7.5
2011-03-23
Unknown · Pre Online Tests Generator Pro · CVE-2010-4776
**Name of the Vulnerable Software and Affected Versions** Pre Online Tests Generator Pro (affected versions not specified) **Description** The issue allows remote attackers to execute arbitrary SQL commands via the `tid2` parameter in the `takefreestart.php` file. This can lead to unauthorized access and manipulation of database content. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2008-5458
7.5
2008-09-22
Unknown · Zanfi Cms Lite · CVE-2008-4159
**Name of the Vulnerable Software and Affected Versions** Jaw Portal (affected versions not specified) Zanfi CMS lite (affected versions not specified) **Description** The issue allows remote attackers to execute arbitrary SQL commands via the `pageid` parameter in the "index.php" file. This can be exploited by sending a malicious request to the `/index.php` endpoint. **Recommendations** For Jaw Portal, update the index.php file to properly sanitize the `pageid` parameter to prevent SQL injection. For Zanfi CMS lite, update the index.php file to properly sanitize the `pageid` parameter to prevent SQL injection. As a temporary workaround, consider restricting access to the index.php file until a patch is available.