phpcollab records
5 published records for vendor phpcollab.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 20%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2017-6090Weaponized | Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to executephpcollab · phpcollab · CWE-434 | High8.8 | — | 96.4% | Oct 2, 2017 |
41Plan | CVE-2008-4304No exploit | general/login.php in phpCollab 2.5 rc3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspeciphpcollab · phpcollab · CWE-78 | Critical10.0 | — | 3.0% | Dec 23, 2008 |
40Plan | CVE-2017-6089Proof of concept | SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or phpcollab · phpcollab · CWE-89 | Critical9.8 | — | 3.0% | Oct 2, 2017 |
39Monitor | CVE-2017-15907No exploit | SQL injection vulnerability in phpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter tophpcollab · phpcollab · CWE-89 | Critical9.8 | — | 1.3% | Oct 26, 2017 |
32Monitor | CVE-2006-1495Proof of concept | SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remnetoffice · netoffice | High7.5 | — | 6.3% | Mar 29, 2006 |
- CVE-2017-609064This week
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute
HighCVSS 8.8WeaponizedEPSS 96%phpcollab · phpcollabOct 2, 2017
- CVE-2008-430441Plan
general/login.php in phpCollab 2.5 rc3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspeci
CriticalCVSS 10.0No exploitEPSS 3%phpcollab · phpcollabDec 23, 2008
- CVE-2017-608940Plan
SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or
CriticalCVSS 9.8Proof of conceptEPSS 3%phpcollab · phpcollabOct 2, 2017
- CVE-2017-1590739Monitor
SQL injection vulnerability in phpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to
CriticalCVSS 9.8No exploitEPSS 1%phpcollab · phpcollabOct 26, 2017
- CVE-2006-149532Monitor
SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows rem
HighCVSS 7.5Proof of conceptEPSS 6%netoffice · netofficeMar 29, 2006