linpha records
12 published records for vendor linpha.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2007-4053Proof of concept | SQL injection vulnerability in include/img_view.class.php in LinPHA 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commalinpha · linpha | High7.5 | — | 2.5% | Jul 30, 2007 |
30Monitor | CVE-2004-2066No exploit | SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication vlinpha · linpha | High7.5 | — | 1.4% | Jul 29, 2004 |
25Monitor | CVE-2006-1924No exploit | SQL injection vulnerability in functions/db_api.php in LinPHA 1.1.1 allows remote attackers to execute arbitrary SQL commands via unknown velinpha · linpha | Medium6.4 | — | 1.3% | Apr 20, 2006 |
23Monitor | CVE-2006-1923No exploit | Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.1.1 allow remote attackers to inject arbitrary web script or HTML vialinpha · linpha | Medium5.8 | — | 1.3% | Apr 20, 2006 |
21Monitor | CVE-2006-0713Proof of concept | Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via ..linpha · linpha | Medium5.0 | — | 3.1% | Feb 15, 2006 |
21Monitor | CVE-2008-1856Proof of concept | plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modifies the configuratiolinpha · linpha · CWE-20 | Medium5.1 | — | 2.7% | Apr 16, 2008 |
20Monitor | CVE-2011-3753No exploit | LinPHA 1.3.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation patlinpha · linpha · CWE-200 | Medium5.0 | — | 1.3% | Sep 23, 2011 |
17Monitor | CVE-2008-7223No exploit | Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.3 allow remote attackers to inject arbitrary web script or HTML vialinpha · linpha · CWE-79 | Medium4.3 | — | 1.2% | Sep 14, 2009 |
17Monitor | CVE-2008-6571No exploit | Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.4 might allow remote attackers to inject arbitrary web script or HTlinpha · linpha · CWE-79 | Medium4.3 | — | 1.1% | Mar 31, 2009 |
17Monitor | CVE-2008-1487No exploit | Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.3 allow remote attackers to inject arbitrary web script or HTML vialinpha · linpha · CWE-79 | Medium4.3 | — | 1.0% | Mar 24, 2008 |
17Monitor | CVE-2014-7265No exploit | Cross-site scripting (XSS) vulnerability in LinPHA allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.linpha · linpha · CWE-79 | Medium4.3 | — | 0.9% | Dec 12, 2014 |
10Monitor | CVE-2006-1848No exploit | Multiple cross-site scripting (XSS) vulnerabilities in stats_view.php in LinPHA 1.1.0 allow remote attackers to inject arbitrary web script linpha · linpha | Low2.6 | — | 1.3% | Apr 19, 2006 |
- CVE-2007-405331Monitor
SQL injection vulnerability in include/img_view.class.php in LinPHA 1.3.1 and earlier allows remote attackers to execute arbitrary SQL comma
HighCVSS 7.5Proof of conceptEPSS 3%linpha · linphaJul 30, 2007
- CVE-2004-206630Monitor
SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication v
HighCVSS 7.5No exploitEPSS 1%linpha · linphaJul 29, 2004
- CVE-2006-192425Monitor
SQL injection vulnerability in functions/db_api.php in LinPHA 1.1.1 allows remote attackers to execute arbitrary SQL commands via unknown ve
MediumCVSS 6.4No exploitEPSS 1%linpha · linphaApr 20, 2006
- CVE-2006-192323Monitor
Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.1.1 allow remote attackers to inject arbitrary web script or HTML via
MediumCVSS 5.8No exploitEPSS 1%linpha · linphaApr 20, 2006
- CVE-2006-071321Monitor
Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via ..
MediumCVSS 5.0Proof of conceptEPSS 3%linpha · linphaFeb 15, 2006
- CVE-2008-185621Monitor
plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modifies the configuratio
MediumCVSS 5.1Proof of conceptEPSS 3%linpha · linphaApr 16, 2008
- CVE-2011-375320Monitor
LinPHA 1.3.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pat
MediumCVSS 5.0No exploitEPSS 1%linpha · linphaSep 23, 2011
- CVE-2008-722317Monitor
Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.3 allow remote attackers to inject arbitrary web script or HTML via
MediumCVSS 4.3No exploitEPSS 1%linpha · linphaSep 14, 2009
- CVE-2008-657117Monitor
Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.4 might allow remote attackers to inject arbitrary web script or HT
MediumCVSS 4.3No exploitEPSS 1%linpha · linphaMar 31, 2009
- CVE-2008-148717Monitor
Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.3 allow remote attackers to inject arbitrary web script or HTML via
MediumCVSS 4.3No exploitEPSS 1%linpha · linphaMar 24, 2008
- CVE-2014-726517Monitor
Cross-site scripting (XSS) vulnerability in LinPHA allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
MediumCVSS 4.3No exploitEPSS 1%linpha · linphaDec 12, 2014
- CVE-2006-184810Monitor
Multiple cross-site scripting (XSS) vulnerabilities in stats_view.php in LinPHA 1.1.0 allow remote attackers to inject arbitrary web script
LowCVSS 2.6No exploitEPSS 1%linpha · linphaApr 19, 2006