Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Zeel Chavda

#11524of 53,633
23.9Total CVSS
Vulnerabilities · 3
Medium
1
High
2
PT-2018-13672
8.8
2018-09-07
Phpmyfaq · Phpmyfaq · CVE-2018-16650
**Name of the Vulnerable Software and Affected Versions** phpMyFAQ versions prior to 2.9.11 **Description** The issue allows for CSRF, which can be exploited by an attacker to perform unintended actions on the affected system. **Recommendations** For versions prior to 2.9.11, update to version 2.9.11 or later to resolve the issue.
PT-2018-13673
9.0
2018-09-07
Phpmyfaq Team · Phpmyfaq · CVE-2018-16651
**Name of the Vulnerable Software and Affected Versions** phpMyFAQ versions prior to 2.9.11 **Description** The issue concerns CSV injection in reports within the admin backend. **Recommendations** For versions prior to 2.9.11, update to version 2.9.11 or later to resolve the issue.
PT-2018-12758
6.1
2018-08-02
Intelliants · Subrion Cms · CVE-2018-14840
**Name of the Vulnerable Software and Affected Versions** Subrion CMS version 4.2.1 **Description** The issue in Subrion CMS allows for XSS due to the `uploads/.htaccess` file not blocking .html file uploads, while it does block other file types such as .htm. **Recommendations** For Subrion CMS version 4.2.1, consider restricting or blocking .html file uploads in the `uploads/.htaccess` file as a temporary workaround until a patch is available.