Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kurdish Hackers Team

Researcher fromKurd-Team
#17973of 53,633
15Total CVSS
Vulnerabilities · 2
High
2
PT-2009-6275
7.5
2009-11-28
Unknown · Radio Istek Scripti · CVE-2009-4096
**Name of the Vulnerable Software and Affected Versions** RADIO istek scripti version 2.5 **Description** The issue allows remote attackers to obtain user credentials due to insufficient access control of sensitive information stored under the web root. This can be achieved via a direct request for estafresgaftesantusyan.inc. **Recommendations** For version 2.5, restrict access to sensitive information stored under the web root to prevent unauthorized access. Consider implementing proper access controls to protect user credentials. As a temporary workaround, consider restricting direct requests for estafresgaftesantusyan.inc until a more permanent solution is available.
PT-2009-5386
7.5
2009-09-03
Dle · Datalife Engine · CVE-2009-3055
Name of the Vulnerable Software and Affected Versions: DataLife Engine (DLE) version 8.2 Description: The issue allows remote attackers to execute arbitrary PHP code via a URL in the `dle config api` parameter in the `engine/api/api.class.php` file. Recommendations: For DataLife Engine (DLE) version 8.2, consider restricting access to the `engine/api/api.class.php` file until a patch is available. As a temporary workaround, avoid using the `dle config api` parameter in the affected API endpoint until the issue is resolved.