Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

D4V00D_Cr4Ck3R

Researcher fromvirangar security team
#36384of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2009-2281
7.5
2009-05-21
Phpwebnews · Phpwebnews · CVE-2008-6812
Name of the Vulnerable Software and Affected Versions: phpWebNews version 0.2 MySQL Edition Description: The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `det` parameter in the bukutamu.php file. Recommendations: For phpWebNews version 0.2 MySQL Edition, consider restricting access to the bukutamu.php file until a patch is available. As a temporary workaround, avoid using the `det` parameter in the affected API endpoint.