Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tom0Li

#20059of 53,624
12.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2018-9694
7.5
2018-04-16
Qingdao Nature Easy Soft · Qingdao Nature Easy Soft Chanzhi Enterprise Portal System · CVE-2018-10122
Name of the Vulnerable Software and Affected Versions: QingDao Nature Easy Soft Chanzhi Enterprise Portal System (aka chanzhieps) version pro1.6 Description: The issue allows remote attackers to read arbitrary files via directory traversal sequences in the `pathname` parameter to "www/file.php" API endpoint. Recommendations: For version pro1.6, restrict access to the "www/file.php" endpoint to minimize the risk of exploitation, and avoid using the `pathname` parameter until the issue is resolved.
PT-2018-9629
5.4
2018-04-11
Catfish · Catfish Cms · CVE-2018-10023
Name of the Vulnerable Software and Affected Versions: Catfish CMS version 4.7.21 Description: The issue allows for XSS via the `pinglun` parameter to the "cat/index/index/pinglun" API endpoint, which is related to an authenticated comment. Recommendations: For Catfish CMS version 4.7.21, avoid using the `pinglun` parameter in the "cat/index/index/pinglun" API endpoint until the issue is resolved. As a temporary workaround, consider restricting access to this endpoint to minimize the risk of exploitation.