Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Steve Christey Coley

#21089of 53,633
11.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2006-3790
7.5
2006-06-06
Rumble · Rumble · CVE-2006-2872
**Name of the Vulnerable Software and Affected Versions** Rumble version 1.02 **Description** The issue allows remote attackers to execute arbitrary PHP code via a URL in the `configArr[pathtodir]` parameter in the config.php file. **Recommendations** For Rumble version 1.02, consider restricting access to the config.php file to minimize the risk of exploitation. As a temporary workaround, avoid using the `configArr[pathtodir]` parameter in the affected config.php file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2006-2282
4.3
2006-03-19
Vpmi · Vpmi Enterprise · CVE-2006-1266
**Name of the Vulnerable Software and Affected Versions** VPMi Enterprise version 3.3 **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the `Request Name Display` parameter in the "Service Requests.asp" file. **Recommendations** For VPMi Enterprise version 3.3, consider restricting access to the `Request Name Display` parameter in the Service Requests.asp file to minimize the risk of exploitation. Avoid using the `Request Name Display` parameter until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.