php-update records
4 published records for vendor php-update.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2006-6661Proof of concept | Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables php-update · php-update | High7.5 | — | 6.7% | Dec 20, 2006 |
31Monitor | CVE-2006-6878Proof of concept | admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] parameter to 1 during a php-update · php-update | High7.5 | — | 2.4% | Dec 31, 2006 |
30Monitor | CVE-2006-6880Proof of concept | Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to execute arbitrary SQL cophp-update · php-update · CWE-89 | High7.5 | — | 1.0% | Dec 31, 2006 |
25Monitor | CVE-2006-6879Proof of concept | Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated users to upload arbitrphp-update · php-update | Medium6.0 | — | 1.9% | Dec 31, 2006 |
- CVE-2006-666132Monitor
Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables
HighCVSS 7.5Proof of conceptEPSS 7%php-update · php-updateDec 20, 2006
- CVE-2006-687831Monitor
admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] parameter to 1 during a
HighCVSS 7.5Proof of conceptEPSS 2%php-update · php-updateDec 31, 2006
- CVE-2006-688030Monitor
Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to execute arbitrary SQL co
HighCVSS 7.5Proof of conceptEPSS 1%php-update · php-updateDec 31, 2006
- CVE-2006-687925Monitor
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated users to upload arbitr
MediumCVSS 6.0Proof of conceptEPSS 2%php-update · php-updateDec 31, 2006