Skip to content
Noroxi

php-proxy records

4 published records for vendor php-proxy.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
25%
Median publish → KEV
No record has entered KEV

All records

4 records
  • In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulne

    HighCVSS 7.5Proof of conceptEPSS 33%

    php-proxy · php-proxyNov 22, 2018

  • PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access

    HighCVSS 7.5Proof of conceptEPSS 22%

    php-proxy · php-proxyNov 13, 2018

  • The str_rot_pass function in vendor/atholn1600/php-proxy/src/helpers.php in PHP-Proxy 5.1.0 uses weak cryptography, which makes it easier fo

    HighCVSS 7.5No exploitEPSS 1%

    php-proxy · php-proxyNov 30, 2018

  • PHP-Proxy through 5.1.0 has Cross-Site Scripting (XSS) via the URL field in index.php.

    MediumCVSS 6.1No exploitEPSS 1%

    php-proxy · php-proxyNov 30, 2018