Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kenneth F. Belva

#26963of 53,633
9.3Total CVSS
Vulnerabilities · 2
Medium
2
PT-2014-7303
4.3
2014-09-30
Unknown · Restaurant Script · CVE-2014-6619
**Name of the Vulnerable Software and Affected Versions** Restaurant Script (PizzaInn Project) version 1.0.0 **Description** The issue allows remote attackers to inject arbitrary web script or HTML via the `fname`, `lname`, or `login` parameters in the register-exec.php file, potentially leading to cross-site scripting (XSS) attacks. **Recommendations** For Restaurant Script (PizzaInn Project) version 1.0.0, consider validating and sanitizing user input for the `fname`, `lname`, and `login` parameters to prevent XSS attacks. As a temporary workaround, restrict access to the register-exec.php file until a patch is available.
PT-2005-3668
5.0
2005-09-02
Simple Php · Simple Php Blog · CVE-2005-2787
**Name of the Vulnerable Software and Affected Versions** Simple PHP Blog (affected versions not specified) **Description** The issue allows remote attackers to delete arbitrary files via the `comment` parameter in the "comment delete cgi.php" file. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.