Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tzitaroth

#19225of 53,624
13.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2006-2079
6.4
2006-03-07
Gregarius · Gregarius · CVE-2006-1042
**Name of the Vulnerable Software and Affected Versions** Gregarius version 0.5.2 **Description** The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the `folder` parameter to "feed.php" or the `rss query` parameter to "search.php". **Recommendations** For Gregarius version 0.5.2, consider restricting access to the "feed.php" and "search.php" scripts until a patch is available. As a temporary workaround, avoid using the `folder` and `rss query` parameters in the affected API endpoints.
PT-2006-1627
7.5
2006-02-06
Loudblog · Loudblog · CVE-2006-0565
**Name of the Vulnerable Software and Affected Versions** Loudblog versions 0.4 and earlier **Description** The issue allows remote attackers to execute arbitrary PHP code via a URL in the `$GLOBALS[path]` parameter in the `inc/backend settings.php` file. **Recommendations** For Loudblog versions 0.4 and earlier, consider restricting access to the `inc/backend settings.php` file to minimize the risk of exploitation. As a temporary workaround, avoid using the `$GLOBALS[path]` parameter in the affected file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.