Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Xiaozhis

#13707of 53,632
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2017-19175
9.8
2017-06-21
Websitebaker · Websitebaker · CVE-2017-9771
**Name of the Vulnerable Software and Affected Versions** WebsiteBaker version 2.10.0 **Description** The issue allows remote attackers to execute arbitrary PHP code. This can be achieved via the `database username`, `database host`, or `database password` parameter in the install/save.php file. **Recommendations** For WebsiteBaker version 2.10.0, consider restricting access to the install/save.php file until a patch is available. As a temporary workaround, avoid using the `database username`, `database host`, and `database password` parameters in the install/save.php file to minimize the risk of exploitation.
PT-2017-19148
9.8
2017-06-18
Projectsend · Projectsend · CVE-2017-9741
**Name of the Vulnerable Software and Affected Versions** ProjectSend version r754 **Description** The issue allows remote attackers to execute arbitrary PHP code via the `dbprefix` parameter in the install/make-config.php file, related to replacing TABLES PREFIX in the configuration file. **Recommendations** For ProjectSend version r754, consider restricting access to the install/make-config.php file until a patch is available, and avoid using the `dbprefix` parameter in this file to minimize the risk of exploitation.