Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jackkong1

#19400of 53,635
13.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2018-14639
7.5
2018-10-29
Lulu · Lulu Cms · CVE-2018-18771
**Name of the Vulnerable Software and Affected Versions** LuLu CMS versions prior to 2015-05-14 **Description** An issue was discovered that allows arbitrary file upload. This is achieved by entering a filename, directory name, and PHP code into the three text input fields in the backendmodulesfilemanagercontrollersDefaultController.php file. **Recommendations** For versions prior to 2015-05-14, restrict access to the backendmodulesfilemanagercontrollersDefaultController.php file to minimize the risk of exploitation. As a temporary workaround, consider disabling the file upload functionality in the DefaultController.php file until a fix is applied.
PT-2018-14505
6.1
2018-10-21
Fiyo · Fiyo Cms · CVE-2018-18545
**Name of the Vulnerable Software and Affected Versions** Fiyo CMS version 2.0.7 **Description** The issue is related to a security problem where an attacker can inject malicious code. The `name` parameter in the "dapurappsapp useredit user.php" endpoint is vulnerable. **Recommendations** For Fiyo CMS version 2.0.7, avoid using the `name` parameter in the "dapurappsapp useredit user.php" endpoint until the issue is resolved.