php-stats records
12 published records for vendor php-stats.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2006-7173Proof of concept | Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP cphp-stats · php-stats | Critical10.0 | — | 3.8% | Mar 20, 2007 |
41Plan | CVE-2006-1085No exploit | admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbiphp-stats · php-stats | Critical10.0 | — | 3.5% | Mar 8, 2006 |
41Plan | CVE-2007-5452Proof of concept | Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arbitrary SQL commands php-stats · php-stats · CWE-89 | Critical10.0 | — | 2.9% | Oct 14, 2007 |
35Monitor | CVE-2007-5453Proof of concept | Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing php-stats · php-stats · CWE-94 | High8.5 | — | 3.9% | Oct 14, 2007 |
31Monitor | CVE-2006-7172Proof of concept | Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitraryphp-stats · php-stats | High7.5 | — | 2.3% | Mar 20, 2007 |
31Monitor | CVE-2006-1083No exploit | Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary php-stats · php-stats | High7.5 | — | 2.2% | Mar 8, 2006 |
30Monitor | CVE-2006-1084No exploit | Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) thephp-stats · php-stats | High7.5 | — | 1.5% | Mar 8, 2006 |
27Monitor | CVE-2006-1087No exploit | Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authentiphp-stats · php-stats | Medium6.5 | — | 1.8% | Mar 8, 2006 |
21Monitor | CVE-2006-1088No exploit | PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, wphp-stats · php-stats | Medium5.0 | — | 1.8% | Mar 8, 2006 |
18Monitor | CVE-2007-4334Proof of concept | Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML viphp-stats · php-stats | Medium4.3 | — | 1.8% | Aug 14, 2007 |
17Monitor | CVE-2007-4917Proof of concept | Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTMLphp-stats · php-stats · CWE-79 | Medium4.3 | — | 1.5% | Sep 17, 2007 |
17Monitor | CVE-2008-6212Proof of concept | Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats 0.1.9.1 allows remote attackers to inject arbitrary web script or HTML viphp-stats · php-stats · CWE-79 | Medium4.3 | — | 1.5% | Feb 19, 2009 |
- CVE-2006-717341Plan
Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP c
CriticalCVSS 10.0Proof of conceptEPSS 4%php-stats · php-statsMar 20, 2007
- CVE-2006-108541Plan
admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbi
CriticalCVSS 10.0No exploitEPSS 4%php-stats · php-statsMar 8, 2006
- CVE-2007-545241Plan
Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arbitrary SQL commands
CriticalCVSS 10.0Proof of conceptEPSS 3%php-stats · php-statsOct 14, 2007
- CVE-2007-545335Monitor
Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing
HighCVSS 8.5Proof of conceptEPSS 4%php-stats · php-statsOct 14, 2007
- CVE-2006-717231Monitor
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitrary
HighCVSS 7.5Proof of conceptEPSS 2%php-stats · php-statsMar 20, 2007
- CVE-2006-108331Monitor
Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary
HighCVSS 7.5No exploitEPSS 2%php-stats · php-statsMar 8, 2006
- CVE-2006-108430Monitor
Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the
HighCVSS 7.5No exploitEPSS 2%php-stats · php-statsMar 8, 2006
- CVE-2006-108727Monitor
Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenti
MediumCVSS 6.5No exploitEPSS 2%php-stats · php-statsMar 8, 2006
- CVE-2006-108821Monitor
PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, w
MediumCVSS 5.0No exploitEPSS 2%php-stats · php-statsMar 8, 2006
- CVE-2007-433418Monitor
Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML vi
MediumCVSS 4.3Proof of conceptEPSS 2%php-stats · php-statsAug 14, 2007
- CVE-2007-491717Monitor
Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML
MediumCVSS 4.3Proof of conceptEPSS 1%php-stats · php-statsSep 17, 2007
- CVE-2008-621217Monitor
Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats 0.1.9.1 allows remote attackers to inject arbitrary web script or HTML vi
MediumCVSS 4.3Proof of conceptEPSS 1%php-stats · php-statsFeb 19, 2009