Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Zero X

#18775of 53,624
14.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2008-3100
4.3
2008-03-28
His · His Webshop · CVE-2008-1541
**Name of the Vulnerable Software and Affected Versions** HIS Webshop version 2.50 **Description** A directory traversal issue exists, allowing remote attackers to read arbitrary files. This is achieved by using a .. (dot dot) in the `t` parameter of the "cgi-bin/his-webshop.pl" endpoint. **Recommendations** For HIS Webshop version 2.50, consider restricting access to the cgi-bin/his-webshop.pl endpoint until a patch is available. As a temporary workaround, avoid using the `t` parameter in the affected endpoint to minimize the risk of exploitation.
PT-2007-7067
10
2007-11-30
K+B · K+B-Bestellsystem · CVE-2007-6176
**Name of the Vulnerable Software and Affected Versions** K+B-Bestellsystem (affected versions not specified) **Description** The issue allows remote attackers to execute arbitrary commands. This can be achieved by using shell metacharacters in the `domain` or `tld` parameters within a `check owner` action. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.