İçeriğe atla
Noroxi

phpx kayıtları

phpx üreticisine ait 12 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
7
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Yıllara göre kayıt

    Çubuk: toplam · koyu kısım: CISA KEV.

    Tekrar eden sınıflar

    Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.

    CWE

    Tüm kayıtlar

    12 kayıt
    • CVE-2004-0249
      41Planlayın

      PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another

      KritikCVSS 10,0Kavram kanıtıEPSS %5

      phpx · phpx23 Kas 2004

    • CVE-2007-1550
      31İzleyin

      Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) c

      YüksekCVSS 7,5Kavram kanıtıEPSS %2

      phpx · phpx20 Mar 2007

    • CVE-2005-3968
      31İzleyin

      SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass auth

      YüksekCVSS 7,5Kavram kanıtıEPSS %2

      phpx · phpx3 Ara 2005

    • CVE-2008-3489
      30İzleyin

      SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers to execute arbitrar

      YüksekCVSS 7,5Kavram kanıtıEPSS %1

      phpx · phpx6 Ağu 2008

    • CVE-2004-0248
      27İzleyin

      Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbit

      OrtaCVSS 6,8İstismar yokEPSS %1

      phpx · phpx23 Kas 2004

    • CVE-2007-1549
      27İzleyin

      Unrestricted file upload vulnerability in gallery.php in phpx 3.5.15 allows remote attackers to upload and execute arbitrary PHP scripts via

      OrtaCVSS 6,8İstismar yokEPSS %1

      phpx · phpx20 Mar 2007

    • CVE-2008-5000
      27İzleyin

      SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows remote attackers to exe

      OrtaCVSS 6,8Kavram kanıtıEPSS %1

      phpx · phpx10 Kas 2008

    • CVE-2004-2364
      23İzleyin

      Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs tha

      OrtaCVSS 5,0Kavram kanıtıEPSS %11

      phpx · phpx31 Ara 2004

    • CVE-2004-2362
      21İzleyin

      PHPX 3.2.6 and earlier allows remote attackers to obtain the physical path of PHPX via a null or invalid value in the limit parameter, which

      OrtaCVSS 5,0İstismar yokEPSS %2

      phpx · phpx31 Ara 2004

    • CVE-2004-2363
      18İzleyin

      Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers t

      OrtaCVSS 4,3Kavram kanıtıEPSS %2

      phpx · phpx31 Ara 2004

    • CVE-2006-0933
      18İzleyin

      Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI i

      OrtaCVSS 4,3Kavram kanıtıEPSS %2

      phpx · phpx28 Şub 2006

    • CVE-2007-1551
      17İzleyin

      Multiple cross-site scripting (XSS) vulnerabilities in phpx 3.5.15 allow remote attackers to inject arbitrary web script or HTML via (1) the

      OrtaCVSS 4,3İstismar yokEPSS %2

      phpx · phpx20 Mar 2007