Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

L1Nk3R

#16934of 53,633
15.9Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2021-17135
9.8
2021-09-23
Unknown · Frogcms Sentcms · CVE-2021-26794
**Name of the Vulnerable Software and Affected Versions** FrogCMS SentCMS version 0.9.5 **Description** The issue allows for privilege escalation in the 'upload.php' file, enabling an attacker to execute arbitrary code by uploading a crafted php file. **Recommendations** For FrogCMS SentCMS version 0.9.5, consider disabling the 'upload.php' file or restricting its access until a patch is available to prevent arbitrary code execution.
PT-2018-9736
6.1
2018-04-17
Bigtree · Bigtree · CVE-2018-10183
Name of the Vulnerable Software and Affected Versions: BigTree version 4.2.22 Description: The issue is related to cross-site scripting (XSS) in the /core/inc/lib/less.php/test/index.php file. This occurs due to the echo of the $ SERVER['REQUEST URI'] variable. The vulnerability can be demonstrated by manipulating the dir parameter in a file=charsets action. Recommendations: For BigTree version 4.2.22, consider restricting access to the vulnerable /core/inc/lib/less.php/test/index.php file until a patch is available. As a temporary workaround, avoid using the dir parameter in the file=charsets action to minimize the risk of exploitation.