Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ded Mustd!E

#17901of 53,639
15Total CVSS
Vulnerabilities · 2
High
2
PT-2009-1591
7.5
2009-02-11
Open Source Matters · Joomla! · CVE-2008-6116
**Name of the Vulnerable Software and Affected Versions** EXtrovert Software Thyme (com thyme) version 1.0 for Joomla! **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the `event` parameter in the "index.php" endpoint. **Recommendations** For version 1.0, consider restricting access to the "index.php" endpoint until a patch is available. As a temporary workaround, avoid using the `event` parameter in the affected endpoint to minimize the risk of exploitation.
PT-2008-2062
7.5
2008-01-23
Qihoo 360 · 360 Web Manager · CVE-2008-0430
**Name of the Vulnerable Software and Affected Versions** 360 Web Manager version 3.0 **Description** A SQL injection issue exists, allowing remote attackers to execute arbitrary SQL commands. This is achieved via the `IDFM` parameter in the form.php file. **Recommendations** For 360 Web Manager version 3.0, avoid using the `IDFM` parameter in the form.php file until a patch is available. As a temporary workaround, consider restricting access to the form.php file to minimize the risk of exploitation.