Skip to content
Noroxi

php-stats records

12 published records for vendor php-stats.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
6
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

12 records
  • Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP c

    CriticalCVSS 10.0Proof of conceptEPSS 4%

    php-stats · php-statsMar 20, 2007

  • admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbi

    CriticalCVSS 10.0No exploitEPSS 4%

    php-stats · php-statsMar 8, 2006

  • Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arbitrary SQL commands

    CriticalCVSS 10.0Proof of conceptEPSS 3%

    php-stats · php-statsOct 14, 2007

  • CVE-2007-5453
    35Monitor

    Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing

    HighCVSS 8.5Proof of conceptEPSS 4%

    php-stats · php-statsOct 14, 2007

  • CVE-2006-7172
    31Monitor

    Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitrary

    HighCVSS 7.5Proof of conceptEPSS 2%

    php-stats · php-statsMar 20, 2007

  • CVE-2006-1083
    31Monitor

    Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary

    HighCVSS 7.5No exploitEPSS 2%

    php-stats · php-statsMar 8, 2006

  • CVE-2006-1084
    30Monitor

    Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the

    HighCVSS 7.5No exploitEPSS 2%

    php-stats · php-statsMar 8, 2006

  • CVE-2006-1087
    27Monitor

    Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenti

    MediumCVSS 6.5No exploitEPSS 2%

    php-stats · php-statsMar 8, 2006

  • CVE-2006-1088
    21Monitor

    PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, w

    MediumCVSS 5.0No exploitEPSS 2%

    php-stats · php-statsMar 8, 2006

  • CVE-2007-4334
    18Monitor

    Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML vi

    MediumCVSS 4.3Proof of conceptEPSS 2%

    php-stats · php-statsAug 14, 2007

  • CVE-2007-4917
    17Monitor

    Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML

    MediumCVSS 4.3Proof of conceptEPSS 1%

    php-stats · php-statsSep 17, 2007

  • CVE-2008-6212
    17Monitor

    Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats 0.1.9.1 allows remote attackers to inject arbitrary web script or HTML vi

    MediumCVSS 4.3Proof of conceptEPSS 1%

    php-stats · php-statsFeb 19, 2009