Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Vinicius777

#36356of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2015-3664
7.5
2015-01-13
Unknown · Simple E-Document · CVE-2014-10020
**Name of the Vulnerable Software and Affected Versions** Simple e-document version 1.31 **Description** A SQL injection issue allows remote attackers to execute arbitrary SQL commands via the `username` parameter in the login.php file. **Recommendations** For version 1.31, avoid using the `username` parameter in the login.php file until the issue is resolved. Consider temporarily restricting access to the login functionality to minimize the risk of exploitation.