Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tr0Uble-Maker

#17674of 53,630
15.2Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2022-10913
9.8
2022-12-15
Seacms · Seacms · CVE-2021-39426
**Name of the Vulnerable Software and Affected Versions** Seacms version 11.4 **Description** An issue was discovered in the /Upload/admin/admin notify.php file, allowing attackers to execute arbitrary PHP code via the `notify1` parameter when the `action` parameter equals 'set'. **Recommendations** For Seacms version 11.4, consider restricting access to the /Upload/admin/admin notify.php file or disabling the `notify1` parameter when the `action` parameter equals 'set' until a patch is available. Avoid using the `notify1` parameter in the affected API endpoint until the issue is resolved.
PT-2022-10914
5.4
2022-12-15
Unknown · 188Jianzhan · CVE-2021-39427
**Name of the Vulnerable Software and Affected Versions** 188Jianzhan version 2.10 **Description** A cross-site scripting issue allows attackers to execute arbitrary code via the `username` parameter to the "/admin/reg.php" API endpoint. **Recommendations** For 188Jianzhan version 2.10, consider disabling the `username` parameter in the "/admin/reg.php" endpoint until a patch is available. Restrict access to the "/admin/reg.php" endpoint to minimize the risk of exploitation.