Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Jinny Ramsmark

#14292of 55,140
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2026-7684
9.8
2026-02-11
Chevere Spa · Chevereto · CVE-2020-37186
**Name of the Vulnerable Software and Affected Versions** Chevereto version 3.13.4 **Description** Remote code execution is possible during the database configuration installation. Attackers can manipulate the database table prefix parameter `table prefix` to write a PHP shell file and execute arbitrary system commands via a crafted POST request. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2019-15893
9.8
2019-12-17
Joomla · K2 · CVE-2019-19634
**Name of the Vulnerable Software and Affected Versions** class.upload.php versions 1.0.0 through 1.0.3 class.upload.php versions 2.0.0 through 2.0.4 **Description** The issue is related to the omission of .pht from the set of dangerous file extensions in class.upload.php, which is similar to a previously known issue. This affects products that use this class, such as the K2 extension for Joomla. **Recommendations** For class.upload.php versions 1.0.0 through 1.0.3, update to a version that includes .pht in the set of dangerous file extensions. For class.upload.php versions 2.0.0 through 2.0.4, update to a version that includes .pht in the set of dangerous file extensions. As a temporary workaround, consider manually adding .pht to the set of dangerous file extensions to prevent potential exploitation.