phpgraphy records
3 published records for vendor phpgraphy.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-6966Proof of concept | phpGraphy before 0.9.13a does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanuphpgraphy · phpgraphy | High7.5 | — | 2.6% | Feb 3, 2007 |
28Monitor | CVE-2006-1888No exploit | phpGraphy 0.9.11 and earlier allows remote attackers to bypass authentication and gain administrator privileges via a direct request to indephpgraphy · phpgraphy · CWE-264 | Medium6.8 | — | 2.2% | Apr 20, 2006 |
18Monitor | CVE-2005-2735No exploit | Cross-site scripting (XSS) vulnerability in phpGraphy 0.9.9a and earlier allows remote attackers to inject arbitrary web script or HTML via phpgraphy · phpgraphy | Medium4.3 | — | 2.0% | Aug 30, 2005 |
- CVE-2006-696631Monitor
phpGraphy before 0.9.13a does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanu
HighCVSS 7.5Proof of conceptEPSS 3%phpgraphy · phpgraphyFeb 3, 2007
- CVE-2006-188828Monitor
phpGraphy 0.9.11 and earlier allows remote attackers to bypass authentication and gain administrator privileges via a direct request to inde
MediumCVSS 6.8No exploitEPSS 2%phpgraphy · phpgraphyApr 20, 2006
- CVE-2005-273518Monitor
Cross-site scripting (XSS) vulnerability in phpGraphy 0.9.9a and earlier allows remote attackers to inject arbitrary web script or HTML via
MediumCVSS 4.3No exploitEPSS 2%phpgraphy · phpgraphyAug 30, 2005