Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Keracker

#20439of 53,619
12.5Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2011-1870
7.5
2011-10-09
Entrans · Entrans · CVE-2010-4935
**Name of the Vulnerable Software and Affected Versions** Entrans versions 0.3.2 and earlier **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `sid` parameter in the "poll.php" file. **Recommendations** For Entrans versions 0.3.2 and earlier, avoid using the `sid` parameter in the "poll.php" file until a fix is available. As a temporary workaround, consider restricting access to the "poll.php" file to minimize the risk of exploitation.
PT-2010-1820
5.0
2010-12-01
Web Wiz · Web Wiz Newspad · CVE-2009-5019
**Name of the Vulnerable Software and Affected Versions** Web Wiz NewsPad (affected versions not specified) **Description** The issue allows remote attackers to download a database due to insufficient access control. Sensitive information is stored under the web root, enabling attackers to access the database via a direct request for database/NewsPad.mdb. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.