Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mcblog

#20104of 53,633
12.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2021-22273
7.5
2021-08-16
Nginx · Nginx · CVE-2021-38712
**Name of the Vulnerable Software and Affected Versions** OneNav version 0.9.12 **Description** The issue allows information disclosure of the onenav.db3 contents. The vendor recommends blocking access via an NGINX configuration file. **Recommendations** For OneNav version 0.9.12, block the access to the onenav.db3 file via an NGINX configuration file as a recommended solution by the vendor.
PT-2021-22274
5.4
2021-08-16
Imgurl · Imgurl · CVE-2021-38713
**Name of the Vulnerable Software and Affected Versions** imgURL version 2.31 **Description** The issue allows for XSS (Cross-Site Scripting) attacks via the X-Forwarded-For HTTP header. **Recommendations** For imgURL version 2.31, consider restricting access to the X-Forwarded-For HTTP header to minimize the risk of XSS attacks until a patch is available.