CVE Report for Damn Vulnerable Web Application (DVWA)

https://nvd.nist.gov/vuln/detail/CVE-2023-39848#VulnChangeHistorySection

In case you need a quick laugh, have a look at this CVE report.

For context: quote DVWA Repo:

Damn Vulnerable Web Application (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goal is to be an aid for security professionals to test their skills and tools in a legal environment, [...].

3 points · 3 comments · view on lemmy.world

3 Comments

Sysosmaster@infosec.pub · 3 pts · 2y (2 replies)

Saved you a click:

REJECTED CVE has been marked "REJECT" in the CVE List. These CVEs are stored in the NVD, but do not show up in search results.

faebudo@infosec.pub · 2 pts · 2y (1 reply)

Originally was:

"DVWA v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at blind\source\high.php."

Source report: https://github.com/KLSEHB/vulnerability-report/blob/c1f3f27286e435d1bd5893a5fea2ffbe9fb55cbd/Dvwa_vulnerability

mike@postit.quantentoast.de · 1 pts · 2y

I thought this would be visible with my link. Specifically shared the "show changes" Link but that doesn't seem to work.