Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ilkerkandemir

#18192of 53,633
15Total CVSS
Vulnerabilities · 2
High
2
PT-2007-3933
7.5
2007-05-11
Php · Phphtmllib · CVE-2007-2614
**Name of the Vulnerable Software and Affected Versions** phpHtmlLib versions 2.4.0 and earlier **Description** The issue allows remote attackers to execute arbitrary PHP code via a URL in the `phphtmllib` parameter. This is a result of a remote file inclusion vulnerability in the examples/widget8.php file. **Recommendations** For versions 2.4.0 and earlier, update to a version later than 2.4.0 to resolve the issue. As a temporary workaround, consider restricting access to the `examples/widget8.php` file to minimize the risk of exploitation. Avoid using the `phphtmllib` parameter in the affected API endpoint until the issue is resolved.
PT-2007-3880
7.5
2007-05-09
Fipscms · Fipscms · CVE-2007-2561
**Name of the Vulnerable Software and Affected Versions** fipsCMS version 2.1 **Description** A SQL injection issue exists, allowing remote attackers to execute arbitrary SQL commands. This is achieved via the `pid` parameter in the "index.asp" file. **Recommendations** For fipsCMS version 2.1, consider restricting access to the `pid` parameter in the "index.asp" file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.