Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Shmilyltyo

#14505of 53,638
18.6Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2022-16793
8.8
2022-02-08
Hybbs2 · Hybbs2 · CVE-2022-24676
**Name of the Vulnerable Software and Affected Versions** HYBBS2 versions 2.3.2 and earlier **Description** The issue allows for arbitrary file upload via a crafted ZIP archive. This is possible due to a problem in the `update code` function in `Admin.php`. **Recommendations** For HYBBS2 versions 2.3.2 and earlier, consider disabling the `update code` function in `Admin.php` to prevent arbitrary file uploads until a fix is available. Restrict access to the `Admin.php` file to minimize the risk of exploitation. Avoid using the `update code` function until the issue is resolved.
PT-2022-16794
9.8
2022-02-08
Hybbs2 · Hybbs2 · CVE-2022-24677
**Name of the Vulnerable Software and Affected Versions** HYBBS2 versions 2.3.2 and earlier **Description** The issue allows remote code execution because it writes plugin-related configuration information to conf.php. This is due to a problem in Admin.php. **Recommendations** For HYBBS2 versions 2.3.2 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.