Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pehelwan

#14533of 53,632
18.6Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2018-18014
8.8
2018-02-21
Danwin · Danwin · CVE-2018-7308
**Name of the Vulnerable Software and Affected Versions** DanWin hosting versions through 2018-02-11 **Description** A CSRF issue was found in `var/www/html/files.php` that allows arbitrary remote users to add, delete, or modify any files in any hosting account. **Recommendations** For versions through 2018-02-11, update to a version released after 2018-02-11 to resolve the issue. As a temporary workaround, consider restricting access to the `files.php` file to minimize the risk of exploitation.
PT-2018-17977
9.8
2018-02-19
Anchor · Anchor · CVE-2018-7251
**Name of the Vulnerable Software and Affected Versions** Anchor version 0.12.3 **Description** An issue was discovered in the `config/error.php` file. The error log is exposed at the "errors.log" URI and contains MySQL credentials if a MySQL error, such as "Too many connections", has occurred. **Recommendations** For Anchor version 0.12.3, consider restricting access to the "errors.log" URI to prevent exposure of MySQL credentials. As a temporary workaround, restrict access to the `config/error.php` file until a patch is available.