Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yoshinori Ohta

Researcher fromBusiness Architects Inc.
#20984of 53,633
11.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2014-5595
7.5
2014-08-19
Osk · Osk Advance-Flow · CVE-2014-3906
**Name of the Vulnerable Software and Affected Versions** OSK Advance-Flow versions 4.41 and earlier OSK Advance-Flow Forms versions 4.41 and earlier **Description** The issue allows remote attackers to execute arbitrary SQL commands. **Recommendations** For OSK Advance-Flow versions 4.41 and earlier, update to a version later than 4.41. For OSK Advance-Flow Forms versions 4.41 and earlier, update to a version later than 4.41.
PT-2008-3735
4.3
2008-10-03
Blosxom · Blosxom · CVE-2008-2236
Name of the Vulnerable Software and Affected Versions: Blosxom versions prior to 2.1.2 Description: A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the `flav` parameter, which is related to the `flavour` variable. This can be exploited by sending malicious input to the `/blosxom.cgi` endpoint. Recommendations: For versions prior to 2.1.2, update to version 2.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the `flav` parameter in the `blosxom.cgi` endpoint to minimize the risk of exploitation.