Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ins3T

#19387of 53,624
13.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2010-1785
6.8
2010-08-25
Irokez · Irokez Cms · CVE-2009-4982
**Name of the Vulnerable Software and Affected Versions** Irokez CMS version 0.7.1 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is possible due to a SQL injection vulnerability in the select function when magic quotes gpc is disabled. The vulnerability can be exploited via the PATH INFO to the default URI. **Recommendations** For Irokez CMS version 0.7.1, consider disabling the select function or restricting access to it until a patch is available. Additionally, enabling magic quotes gpc can help mitigate the risk of SQL injection attacks.
PT-2010-1360
6.8
2010-01-04
Mini Cms · Mini Cms · CVE-2009-4540
**Name of the Vulnerable Software and Affected Versions** Mini CMS version 1.0.1 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `id` parameter in the "page.php" file. **Recommendations** For Mini CMS version 1.0.1, consider restricting access to the `id` parameter in the "page.php" file to minimize the risk of exploitation.