Vulnerabilities > Gouguoyin
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-05-14 | CVE-2018-11032 | SQL Injection vulnerability in Gouguoyin PHPrap PHPRAP 1.0.4 through 1.0.8 has SQL Injection via the application/home/controller/project.php search() function. | 9.8 |
2018-05-14 | CVE-2018-11031 | Server-Side Request Forgery (SSRF) vulnerability in Gouguoyin PHPrap application/home/controller/debug.php in PHPRAP 1.0.4 through 1.0.8 has SSRF via the /debug URI, as demonstrated by an api[url]=file:////etc/passwd&api[method]=get POST request. | 9.8 |