Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mi4Night

#20091of 53,624
12.9Total CVSS
Vulnerabilities · 2
Medium
2
PT-2009-4236
6.4
2009-05-22
Lightopencms · Lightopencms · CVE-2009-1766
Name of the Vulnerable Software and Affected Versions: LightOpenCMS version 0.1 Description: The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `id` parameter in the "index.php" file. Recommendations: For LightOpenCMS version 0.1, consider restricting access to the `id` parameter in the "index.php" file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2008-5616
6.5
2008-09-30
Unknown · Camera Life · CVE-2008-4366
Name of the Vulnerable Software and Affected Versions: Camera Life version 2.6.2b4 Description: The issue allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to the image upload component, and then accessing it via a direct request to the file in a user directory under images/photos/upload. Recommendations: For version 2.6.2b4, consider restricting access to the image upload component to prevent uploading files with executable extensions until a fix is available. As a temporary workaround, restrict access to the user directory under images/photos/upload to minimize the risk of exploitation.