phpadsnew records
14 published records for vendor phpadsnew.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-3984Proof of concept | PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later versions, with phpAdsNewphpadsnew · phpadsnew | High7.5 | — | 3.2% | Aug 4, 2006 |
31Monitor | CVE-2005-3646No exploit | Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote atphpadsnew · phpadsnew · CWE-89 | High7.5 | — | 2.2% | Nov 17, 2005 |
31Monitor | CVE-2007-0486No exploit | Multiple PHP remote file inclusion vulnerabilities in Openads (aka phpAdsNew) 2.0.7 allow remote attackers to execute arbitrary PHP code viaphpadsnew · phpadsnew · CWE-94 | High7.5 | — | 1.8% | Jan 24, 2007 |
30Monitor | CVE-2001-1054No exploit | PHPAdsNew PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir vphpadsnew · phpadsnew | High7.5 | — | 1.6% | Oct 2, 2001 |
30Monitor | CVE-2006-6415No exploit | PHP remote file inclusion vulnerability in admin/lib-maintenance.inc.php in phpAdsNew 2.0.4-pr2 allows remote attackers to execute arbitraryphpadsnew · phpadsnew | High7.5 | — | 1.4% | Dec 10, 2006 |
30Monitor | CVE-2005-2636No exploit | SQL injection vulnerability in lib-view-direct.inc.php in phpAdsNew and phpPgAds before 2.0.6 allows remote attackers to execute arbitrary Sphpadsnew · phpadsnew | High7.5 | — | 1.2% | Aug 23, 2005 |
21Monitor | CVE-2005-3645No exploit | phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allows remote attackers to obtain the application installation path and other senphpadsnew · phpadsnew · CWE-200 | Medium5.0 | — | 2.3% | Nov 17, 2005 |
21Monitor | CVE-2005-2635No exploit | Multiple directory traversal vulnerabilities in phpAdsNew and phpPgAds before 2.0.6 allow remote attackers to include arbitrary files via a phpadsnew · phpadsnew | Medium5.0 | — | 1.8% | Aug 23, 2005 |
20Monitor | CVE-2006-5437No exploit | Directory traversal vulnerability in upgrade.php in phpAdsNew 2.0.8 allows remote attackers to read arbitrary files via a ..phpadsnew · phpadsnew | Medium5.0 | — | 1.7% | Oct 20, 2006 |
20Monitor | CVE-2005-0790No exploit | phpAdsNew 2.0.4 allows remote attackers to obtain sensitive information via a direct request to (1) lib-xmlrpcs.inc.php, (2) maintenance-actphpadsnew · phpadsnew | Medium5.0 | — | 1.4% | Mar 14, 2005 |
20Monitor | CVE-2005-3791No exploit | HTTP response splitting vulnerability in phpAdsNew and phpPgAds 2.0.6 and earlier allows remote attackers to inject arbitrary HTML headers vphpadsnew · phpadsnew | Medium5.0 | — | 1.0% | Nov 24, 2005 |
18Monitor | CVE-2005-0791Proof of concept | Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers tophpadsnew · phpadsnew | Medium4.3 | — | 4.0% | Mar 14, 2005 |
18Monitor | CVE-2006-1397No exploit | Multiple cross-site scripting (XSS) vulnerabilities in (a) phpAdsNew and (b) phpPgAds before 2.0.8 allow remote attackers to inject arbitrarphpadsnew · phpadsnew | Medium4.3 | — | 1.9% | Mar 28, 2006 |
17Monitor | CVE-2006-5515No exploit | Cross-site scripting (XSS) vulnerability in lib-history.inc.php in phpAdsNew and phpPgAds before 2.0.8-pr1 allows remote attackers to injectphpadsnew · phpadsnew | Medium4.3 | — | 1.6% | Oct 26, 2006 |
- CVE-2006-398431Monitor
PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later versions, with phpAdsNew
HighCVSS 7.5Proof of conceptEPSS 3%phpadsnew · phpadsnewAug 4, 2006
- CVE-2005-364631Monitor
Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote at
HighCVSS 7.5No exploitEPSS 2%phpadsnew · phpadsnewNov 17, 2005
- CVE-2007-048631Monitor
Multiple PHP remote file inclusion vulnerabilities in Openads (aka phpAdsNew) 2.0.7 allow remote attackers to execute arbitrary PHP code via
HighCVSS 7.5No exploitEPSS 2%phpadsnew · phpadsnewJan 24, 2007
- CVE-2001-105430Monitor
PHPAdsNew PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir v
HighCVSS 7.5No exploitEPSS 2%phpadsnew · phpadsnewOct 2, 2001
- CVE-2006-641530Monitor
PHP remote file inclusion vulnerability in admin/lib-maintenance.inc.php in phpAdsNew 2.0.4-pr2 allows remote attackers to execute arbitrary
HighCVSS 7.5No exploitEPSS 1%phpadsnew · phpadsnewDec 10, 2006
- CVE-2005-263630Monitor
SQL injection vulnerability in lib-view-direct.inc.php in phpAdsNew and phpPgAds before 2.0.6 allows remote attackers to execute arbitrary S
HighCVSS 7.5No exploitEPSS 1%phpadsnew · phpadsnewAug 23, 2005
- CVE-2005-364521Monitor
phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allows remote attackers to obtain the application installation path and other sen
MediumCVSS 5.0No exploitEPSS 2%phpadsnew · phpadsnewNov 17, 2005
- CVE-2005-263521Monitor
Multiple directory traversal vulnerabilities in phpAdsNew and phpPgAds before 2.0.6 allow remote attackers to include arbitrary files via a
MediumCVSS 5.0No exploitEPSS 2%phpadsnew · phpadsnewAug 23, 2005
- CVE-2006-543720Monitor
Directory traversal vulnerability in upgrade.php in phpAdsNew 2.0.8 allows remote attackers to read arbitrary files via a ..
MediumCVSS 5.0No exploitEPSS 2%phpadsnew · phpadsnewOct 20, 2006
- CVE-2005-079020Monitor
phpAdsNew 2.0.4 allows remote attackers to obtain sensitive information via a direct request to (1) lib-xmlrpcs.inc.php, (2) maintenance-act
MediumCVSS 5.0No exploitEPSS 1%phpadsnew · phpadsnewMar 14, 2005
- CVE-2005-379120Monitor
HTTP response splitting vulnerability in phpAdsNew and phpPgAds 2.0.6 and earlier allows remote attackers to inject arbitrary HTML headers v
MediumCVSS 5.0No exploitEPSS 1%phpadsnew · phpadsnewNov 24, 2005
- CVE-2005-079118Monitor
Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to
MediumCVSS 4.3Proof of conceptEPSS 4%phpadsnew · phpadsnewMar 14, 2005
- CVE-2006-139718Monitor
Multiple cross-site scripting (XSS) vulnerabilities in (a) phpAdsNew and (b) phpPgAds before 2.0.8 allow remote attackers to inject arbitrar
MediumCVSS 4.3No exploitEPSS 2%phpadsnew · phpadsnewMar 28, 2006
- CVE-2006-551517Monitor
Cross-site scripting (XSS) vulnerability in lib-history.inc.php in phpAdsNew and phpPgAds before 2.0.8-pr1 allows remote attackers to inject
MediumCVSS 4.3No exploitEPSS 2%phpadsnew · phpadsnewOct 26, 2006