Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tmh

#18781of 53,624
14.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2009-3877
6.8
2009-04-20
Chcounter · Chcounter · CVE-2009-1347
**Name of the Vulnerable Software and Affected Versions** chCounter version 3.1.3 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the `login name` parameter (also known as the username field) or the `login pw` parameter (also known as the password field) in the stats/index.php file. **Recommendations** For chCounter version 3.1.3, avoid using the `login name` and `login pw` parameters in the stats/index.php file until the issue is resolved. As a temporary workaround, consider restricting access to the stats/index.php file to minimize the risk of exploitation.
PT-2008-5605
7.5
2008-09-30
Powie · Powie Pscript Forum · CVE-2008-4355
Name of the Vulnerable Software and Affected Versions: Powie PSCRIPT Forum (aka PHP Forum or pForum) versions 1.30 and earlier Description: The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `id` parameter in the "showprofil.php" file. Recommendations: For versions 1.30 and earlier, consider restricting access to the "showprofil.php" file until a patch is available. As a temporary workaround, avoid using the `id` parameter in the affected file to minimize the risk of exploitation.