Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lum Member

#21107of 53,635
11.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2011-1942
4.3
2011-11-02
Utstats · Utstats · CVE-2010-5007
**Name of the Vulnerable Software and Affected Versions** UTStats versions Beta 4 and earlier **Description** The issue is related to a cross-site scripting (XSS) vulnerability. This vulnerability allows remote attackers to inject arbitrary web script or HTML via the `mid` parameter in the "pages/match report.php" file. **Recommendations** For versions Beta 4 and earlier, consider restricting access to the "pages/match report.php" file until a patch is available. As a temporary workaround, avoid using the `mid` parameter in the affected file to minimize the risk of exploitation.
PT-2011-1944
7.5
2011-11-02
Utstats · Utstats · CVE-2010-5009
**Name of the Vulnerable Software and Affected Versions** UTStats versions Beta 4 and earlier **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `pid` parameter in a "matchp" action in the index.php file. **Recommendations** For versions Beta 4 and earlier, avoid using the `pid` parameter in the "matchp" action until a fix is available. As a temporary workaround, consider restricting access to the index.php file to minimize the risk of exploitation.