phpheaven records
9 published records for vendor phpheaven.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-5088No exploit | PHP remote file inclusion vulnerability in connected_users.lib.php3 in phpHeaven phpMyChat 0.1 allows remote attackers to execute arbitrary phpheaven · phpmychat | High7.5 | — | 1.8% | Sep 29, 2006 |
30Monitor | CVE-2001-1357No exploit | Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consphpheaven · phpmychat | High7.5 | — | 1.1% | Feb 7, 2001 |
28Monitor | CVE-2001-1358No exploit | Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library fphpheaven · phpmychat | High7.2 | — | 0.7% | Feb 7, 2001 |
25Monitor | CVE-2006-1669No exploit | SQL injection vulnerability in chat/messagesL.php3 in phpHeaven Team PHPMyChat 0.14.5 and earlier allows remote attackers to execute arbitraphpheaven · phpmychat | Medium6.4 | — | 1.7% | Apr 7, 2006 |
21Monitor | CVE-2006-5897No exploit | Multiple directory traversal vulnerabilities in PhpMyChat Plus 1.9 and earlier allow remote attackers to read arbitrary files via a ..phpheaven · phpmychat plus · CWE-22 | Medium5.0 | — | 1.7% | Nov 15, 2006 |
20Monitor | CVE-2006-5898No exploit | Directory traversal vulnerability in localization/languages.lib.php3 in PhpMyChat 0.14.5 and earlier allows remote attackers to read arbitraphpheaven · phpmychat | Medium5.0 | — | 1.6% | Nov 15, 2006 |
18Monitor | CVE-2005-3991Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in phpMyChat 0.14.6 allow remote attackers to inject arbitrary web script or HTML via thphpheaven · phpmychat | Medium4.3 | — | 1.8% | Dec 4, 2005 |
18Monitor | CVE-2005-1619Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat phpheaven · phpmychat · CWE-79 | Medium4.3 | — | 1.7% | May 16, 2005 |
17Monitor | CVE-2008-1504Proof of concept | Cross-site scripting (XSS) vulnerability in setup.php3 in phpHeaven phpMyChat 0.14.5 allows remote attackers to inject arbitrary web script phpheaven · phpmychat · CWE-79 | Medium4.3 | — | 1.2% | Mar 25, 2008 |
- CVE-2006-508831Monitor
PHP remote file inclusion vulnerability in connected_users.lib.php3 in phpHeaven phpMyChat 0.1 allows remote attackers to execute arbitrary
HighCVSS 7.5No exploitEPSS 2%phpheaven · phpmychatSep 29, 2006
- CVE-2001-135730Monitor
Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown cons
HighCVSS 7.5No exploitEPSS 1%phpheaven · phpmychatFeb 7, 2001
- CVE-2001-135828Monitor
Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library f
HighCVSS 7.2No exploitEPSS 1%phpheaven · phpmychatFeb 7, 2001
- CVE-2006-166925Monitor
SQL injection vulnerability in chat/messagesL.php3 in phpHeaven Team PHPMyChat 0.14.5 and earlier allows remote attackers to execute arbitra
MediumCVSS 6.4No exploitEPSS 2%phpheaven · phpmychatApr 7, 2006
- CVE-2006-589721Monitor
Multiple directory traversal vulnerabilities in PhpMyChat Plus 1.9 and earlier allow remote attackers to read arbitrary files via a ..
MediumCVSS 5.0No exploitEPSS 2%phpheaven · phpmychat plusNov 15, 2006
- CVE-2006-589820Monitor
Directory traversal vulnerability in localization/languages.lib.php3 in PhpMyChat 0.14.5 and earlier allows remote attackers to read arbitra
MediumCVSS 5.0No exploitEPSS 2%phpheaven · phpmychatNov 15, 2006
- CVE-2005-399118Monitor
Multiple cross-site scripting (XSS) vulnerabilities in phpMyChat 0.14.6 allow remote attackers to inject arbitrary web script or HTML via th
MediumCVSS 4.3Proof of conceptEPSS 2%phpheaven · phpmychatDec 4, 2005
- CVE-2005-161918Monitor
Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat
MediumCVSS 4.3Proof of conceptEPSS 2%phpheaven · phpmychatMay 16, 2005
- CVE-2008-150417Monitor
Cross-site scripting (XSS) vulnerability in setup.php3 in phpHeaven phpMyChat 0.14.5 allows remote attackers to inject arbitrary web script
MediumCVSS 4.3Proof of conceptEPSS 1%phpheaven · phpmychatMar 25, 2008