Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mozako

Researcher fromBADROOT SECURITY GROUP
#21044of 53,624
11.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2005-3095
4.3
2005-07-06
Unknown · Autoindex Php Script · CVE-2005-2163
Name of the Vulnerable Software and Affected Versions: AutoIndex PHP Script version 1.5.2 Description: A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the `search` parameter in the "index.php" file. Recommendations: For AutoIndex PHP Script version 1.5.2, consider validating and sanitizing user input for the `search` parameter to prevent XSS attacks. As a temporary workaround, restrict access to the "index.php" file until a patch is available.
PT-2005-3050
7.5
2005-07-01
Community Link · Community Link Pro Web Editor · CVE-2005-2111
Name of the Vulnerable Software and Affected Versions: Community Link Pro Web Editor (affected versions not specified) Description: The issue allows remote attackers to execute arbitrary commands via the `file` parameter in the "login.cgi" endpoint. Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.