Skip to content
Noroxi

php-update records

4 published records for vendor php-update.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    4 records
    • CVE-2006-6661
      32Monitor

      Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables

      HighCVSS 7.5Proof of conceptEPSS 7%

      php-update · php-updateDec 20, 2006

    • CVE-2006-6878
      31Monitor

      admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] parameter to 1 during a

      HighCVSS 7.5Proof of conceptEPSS 2%

      php-update · php-updateDec 31, 2006

    • CVE-2006-6880
      30Monitor

      Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to execute arbitrary SQL co

      HighCVSS 7.5Proof of conceptEPSS 1%

      php-update · php-updateDec 31, 2006

    • CVE-2006-6879
      25Monitor

      Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated users to upload arbitr

      MediumCVSS 6.0Proof of conceptEPSS 2%

      php-update · php-updateDec 31, 2006