Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Enter_The_Dragon

#17916of 53,633
15Total CVSS
Vulnerabilities · 2
High
2
PT-2008-2136
7.5
2008-01-31
WordPress · Adserve Plugin For Wordpress · CVE-2008-0507
**Name of the Vulnerable Software and Affected Versions** AdServe plugin for WordPress version 0.2 **Description** The issue allows remote attackers to execute arbitrary SQL commands via the `id` parameter in the adclick.php file. This can lead to unauthorized access and manipulation of database content. **Recommendations** For AdServe plugin for WordPress version 0.2, consider restricting access to the adclick.php file or avoiding the use of the `id` parameter until a patch is available. As a temporary workaround, disabling the execution of arbitrary SQL commands in the adclick.php file can help minimize the risk of exploitation.
PT-2008-2149
7.5
2008-01-31
WordPress · Wassup · CVE-2008-0520
**Name of the Vulnerable Software and Affected Versions** WassUp plugin versions 1.4 through 1.4.3 for WordPress **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `from date` or `to date` parameter to "spy.php". **Recommendations** For WassUp plugin versions 1.4 through 1.4.3, consider updating to a version that is not affected by this issue, as no specific fix is provided for these versions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.