Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ismail Belkacim

#20333of 53,635
12.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2017-11744
6.1
2017-07-08
Phpldapadmin · Phpldapadmin · CVE-2017-11107
**Name of the Vulnerable Software and Affected Versions** phpLDAPadmin versions prior to 1.2.3 **Description** The issue is related to XSS in the htdocs/entry chooser.php file, which can be exploited via the `form`, `element`, `rdn`, or `container` parameter. **Recommendations** For versions prior to 1.2.3, update to a version that contains a fix for this issue to prevent exploitation.
PT-2015-4220
6.5
2015-01-02
Pmb · Pmb · CVE-2014-9457
**Name of the Vulnerable Software and Affected Versions** PMB versions 4.1.3 and earlier **Description** The issue allows remote authenticated users to execute arbitrary SQL commands. This is achieved by exploiting the `id` parameter in the catalog.php file, which is vulnerable to SQL injection. **Recommendations** For PMB versions 4.1.3 and earlier, consider restricting access to the catalog.php file until a patch is available. As a temporary workaround, avoid using the `id` parameter in the catalog.php file to minimize the risk of exploitation.