Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pd1R

Researcher fromChaitin Tech
#13686of 53,624
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2021-11271
9.8
2021-09-08
Ppgo Jobs · Ppgo Jobs · CVE-2020-26772
Name of the Vulnerable Software and Affected Versions: PPGo Jobs version 2.8.0 Description: The issue allows remote attackers to execute arbitrary code via the `AjaxRun()` function. This enables attackers to inject commands, potentially leading to unauthorized access or control. Recommendations: For PPGo Jobs version 2.8.0, consider disabling the `AjaxRun()` function as a temporary workaround until a patch is available. Restrict access to this function to minimize the risk of exploitation.
PT-2021-21270
9.8
2021-09-08
Showdoc · Showdoc · CVE-2021-36440
**Name of the Vulnerable Software and Affected Versions** ShowDoc version 2.9.5 **Description** The issue allows remote attackers to execute arbitrary code via the `file url` parameter in the AdminUpdateController.class.php component. This enables attackers to upload files without restrictions, potentially leading to code execution. **Recommendations** For ShowDoc version 2.9.5, consider restricting access to the `file url` parameter in the AdminUpdateController.class.php component to minimize the risk of exploitation. As a temporary workaround, avoid using the `file url` parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.