Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Fred777

#18053of 53,630
15Total CVSS
Vulnerabilities · 2
High
2
PT-2010-4947
7.5
2010-09-24
Ib · Ibphotohost · CVE-2010-3601
**Name of the Vulnerable Software and Affected Versions** ibPhotohost version 1.1.2 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `img` parameter in the "index.php" file. **Recommendations** For ibPhotohost version 1.1.2, update to a newer version that contains a fix for this issue.
PT-2010-2531
7.5
2010-03-02
Invision Power · Invision Power Board · CVE-2010-0802
**Name of the Vulnerable Software and Affected Versions** Invision Power Board (nv2) Awards version 1.1.0 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the `id` parameter in a 'view' action within the index.php file. **Recommendations** For version 1.1.0, avoid using the `id` parameter in the affected API endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the index.php file to minimize the risk of exploitation.