Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Postmodern

#20488of 53,622
12.5Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2017-5976
5.0
2017-09-06
Ruby · Ruby · CVE-2014-6438
Name of the Vulnerable Software and Affected Versions: Ruby versions prior to 1.9.2-p330 Description: The issue allows remote attackers to cause a denial of service via a crafted string, potentially leading to catastrophic regular expression backtracking, resource consumption, or application crash. This is due to a problem in the URI.decode www form component method. Recommendations: For versions prior to 1.9.2-p330, update to version 1.9.2-p330 or later to resolve the issue.
PT-2012-4737
7.5
2012-08-12
Ushahidi · Ushahidi Platform · CVE-2012-3468
**Name of the Vulnerable Software and Affected Versions** Ushahidi Platform versions prior to 2.5 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved through vectors related to (1) the `verify` function in `application/controllers/alerts.php`, (2) the `save all` function in `application/models/settings.php`, or (3) the media type to the `timeline` function in `application/controllers/json.php`. **Recommendations** For versions prior to 2.5, update to version 2.5 or later to resolve the issue.