php-collab records
3 published records for vendor php-collab.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2008-4305No exploit | Static code injection vulnerability in installation/setup.php in phpCollab 2.5 rc3 and earlier allows remote authenticated administrators tophp-collab · php-collab · CWE-94 | Critical9.0 | — | 3.1% | Dec 23, 2008 |
27Monitor | CVE-2008-4303No exploit | Multiple SQL injection vulnerabilities in phpCollab 2.5 rc3, 2.4, and earlier allow remote attackers to execute arbitrary SQL commands via tphp-collab · php-collab · CWE-89 | Medium6.8 | — | 1.2% | Dec 23, 2008 |
20Monitor | CVE-2011-3772No exploit | phpCollab 2.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation paphp-collab · phpcollab · CWE-200 | Medium5.0 | — | 1.2% | Sep 23, 2011 |
- CVE-2008-430537Monitor
Static code injection vulnerability in installation/setup.php in phpCollab 2.5 rc3 and earlier allows remote authenticated administrators to
CriticalCVSS 9.0No exploitEPSS 3%php-collab · php-collabDec 23, 2008
- CVE-2008-430327Monitor
Multiple SQL injection vulnerabilities in phpCollab 2.5 rc3, 2.4, and earlier allow remote attackers to execute arbitrary SQL commands via t
MediumCVSS 6.8No exploitEPSS 1%php-collab · php-collabDec 23, 2008
- CVE-2011-377220Monitor
phpCollab 2.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pa
MediumCVSS 5.0No exploitEPSS 1%php-collab · phpcollabSep 23, 2011