Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Wjp911

#13411of 53,624
19.8Total CVSS
Vulnerabilities · 2
Critical
2
PT-2023-16524
9.8
2023-02-11
Ecshop · Ecshop · CVE-2023-0783
**Name of the Vulnerable Software and Affected Versions** EcShop version 4.1.5 **Description** A critical issue affects the PHP File Handler component, specifically the /ecshop/admin/template.php file, leading to unrestricted upload. The attack can be initiated remotely. **Recommendations** For EcShop version 4.1.5, consider disabling the upload functionality in the PHP File Handler component until a patch is available. Restrict access to the /ecshop/admin/template.php file to minimize the risk of exploitation.
PT-2023-7624
10
2023-02-11
Tenda · Tenda Ac23 · CVE-2023-0782
**Name of the Vulnerable Software and Affected Versions** Tenda AC23 version 16.03.07.45 **Description** The issue is related to a stack-based buffer overflow in the `formSetSysToolDDNS/formGetSysToolDDNS` function of the `/bin/httpd` file. This can be exploited by a remote attacker to cause a denial of service. The attack may be launched remotely. **Recommendations** For Tenda AC23 version 16.03.07.45, as a temporary workaround, consider disabling the `formSetSysToolDDNS/formGetSysToolDDNS` function until a patch is available. Restrict access to the `/bin/httpd` file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.