Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nafsh

Researcher fromCyberwh.org
#35442of 53,625
7.5Total CVSS
Vulnerabilities · 1
PT-2012-2177
7.5
2012-09-23
Dedecms · Dedecms · CVE-2011-5200
**Name of the Vulnerable Software and Affected Versions** DeDeCMS version 5.6 **Description** The issue concerns SQL injection vulnerabilities that allow remote attackers to execute arbitrary SQL commands. This can be achieved by manipulating the `id` parameter in the following API endpoints: "list.php", "members.php", or "book.php". **Recommendations** For DeDeCMS version 5.6, as a temporary workaround, consider restricting access to the `id` parameter in the affected API endpoints until a patch is available. Avoid using the `id` parameter in the "list.php", "members.php", and "book.php" endpoints to minimize the risk of exploitation.