phpkit records
20 published records for vendor phpkit.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 9
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2016-10758No exploit | PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via thephpkit · phpkit · CWE-434 | High8.8 | — | 1.6% | May 24, 2019 |
31Monitor | CVE-2005-2683Proof of concept | Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameterphpkit · phpkit | High7.5 | — | 2.4% | Aug 23, 2005 |
31Monitor | CVE-2005-3553No exploit | Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL commandphpkit · phpkit · CWE-89 | High7.5 | — | 1.9% | Nov 16, 2005 |
30Monitor | CVE-2006-7115No exploit | SQL injection vulnerability in PHPKit 1.6.1 RC2 allows remote attackers to inject arbitrary SQL commands via the catid parameter to include.phpkit · phpkit | High7.5 | — | 1.4% | Mar 5, 2007 |
30Monitor | CVE-2004-1538No exploit | SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the phpkit · phpkit | High7.5 | — | 1.3% | Dec 31, 2004 |
30Monitor | CVE-2007-6134Proof of concept | SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via thephpkit · phpkit · CWE-89 | High7.5 | — | 1.1% | Nov 27, 2007 |
30Monitor | CVE-2007-0179Proof of concept | SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid paramephpkit · phpkit | High7.5 | — | 1.1% | Jan 10, 2007 |
28Monitor | CVE-2003-1187Proof of concept | Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script ophpkit · phpkit | Medium6.8 | — | 4.2% | Nov 2, 2003 |
27Monitor | CVE-2005-4424No exploit | Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a phpkit · phpkit | Medium6.5 | — | 1.7% | Dec 20, 2005 |
27Monitor | CVE-2006-1507No exploit | Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error paramphpkit · phpkit | Medium6.8 | — | 1.5% | Mar 29, 2006 |
27Monitor | CVE-2008-7193No exploit | PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by rphpkit · phpkit · CWE-352 | Medium6.8 | — | 0.6% | Sep 9, 2009 |
25Monitor | CVE-2006-0785No exploit | Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arphpkit · phpkit | Medium6.4 | — | 1.6% | Feb 19, 2006 |
25Monitor | CVE-2006-1773Proof of concept | SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands vphpkit · phpkit | Medium6.4 | — | 1.1% | Apr 13, 2006 |
21Monitor | CVE-2005-3554No exploit | Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote phpkit · phpkit · CWE-94 | Medium5.1 | — | 3.4% | Nov 16, 2005 |
21Monitor | CVE-2006-0786Proof of concept | Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackephpkit · phpkit | Medium5.1 | — | 2.4% | Feb 19, 2006 |
18Monitor | CVE-2005-3552No exploit | Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or phpkit · phpkit · CWE-79 | Medium4.3 | — | 2.0% | Nov 16, 2005 |
18Monitor | CVE-2015-1052No exploit | Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT 1.6.6 (Build 160014) allows remote attackers to inject arbitrary web phpkit · phpkit · CWE-79 | Medium4.3 | — | 1.9% | Jan 15, 2015 |
18Monitor | CVE-2004-1537Proof of concept | Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web scriptphpkit · phpkit | Medium4.3 | — | 1.8% | Dec 31, 2004 |
18Monitor | CVE-2005-2699No exploit | Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PHphpkit · phpkit | Medium4.6 | — | 0.5% | Aug 26, 2005 |
17Monitor | CVE-2004-1879No exploit | Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum mephpkit · phpkit | Medium4.3 | — | 1.2% | Dec 31, 2004 |
- CVE-2016-1075835Monitor
PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the
HighCVSS 8.8No exploitEPSS 2%phpkit · phpkitMay 24, 2019
- CVE-2005-268331Monitor
Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter
HighCVSS 7.5Proof of conceptEPSS 2%phpkit · phpkitAug 23, 2005
- CVE-2005-355331Monitor
Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL command
HighCVSS 7.5No exploitEPSS 2%phpkit · phpkitNov 16, 2005
- CVE-2006-711530Monitor
SQL injection vulnerability in PHPKit 1.6.1 RC2 allows remote attackers to inject arbitrary SQL commands via the catid parameter to include.
HighCVSS 7.5No exploitEPSS 1%phpkit · phpkitMar 5, 2007
- CVE-2004-153830Monitor
SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5No exploitEPSS 1%phpkit · phpkitDec 31, 2004
- CVE-2007-613430Monitor
SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5Proof of conceptEPSS 1%phpkit · phpkitNov 27, 2007
- CVE-2007-017930Monitor
SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parame
HighCVSS 7.5Proof of conceptEPSS 1%phpkit · phpkitJan 10, 2007
- CVE-2003-118728Monitor
Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script o
MediumCVSS 6.8Proof of conceptEPSS 4%phpkit · phpkitNov 2, 2003
- CVE-2005-442427Monitor
Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a
MediumCVSS 6.5No exploitEPSS 2%phpkit · phpkitDec 20, 2005
- CVE-2006-150727Monitor
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error param
MediumCVSS 6.8No exploitEPSS 1%phpkit · phpkitMar 29, 2006
- CVE-2008-719327Monitor
PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by r
MediumCVSS 6.8No exploitEPSS 1%phpkit · phpkitSep 9, 2009
- CVE-2006-078525Monitor
Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute ar
MediumCVSS 6.4No exploitEPSS 2%phpkit · phpkitFeb 19, 2006
- CVE-2006-177325Monitor
SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands v
MediumCVSS 6.4Proof of conceptEPSS 1%phpkit · phpkitApr 13, 2006
- CVE-2005-355421Monitor
Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote
MediumCVSS 5.1No exploitEPSS 3%phpkit · phpkitNov 16, 2005
- CVE-2006-078621Monitor
Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attacke
MediumCVSS 5.1Proof of conceptEPSS 2%phpkit · phpkitFeb 19, 2006
- CVE-2005-355218Monitor
Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or
MediumCVSS 4.3No exploitEPSS 2%phpkit · phpkitNov 16, 2005
- CVE-2015-105218Monitor
Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT 1.6.6 (Build 160014) allows remote attackers to inject arbitrary web
MediumCVSS 4.3No exploitEPSS 2%phpkit · phpkitJan 15, 2015
- CVE-2004-153718Monitor
Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script
MediumCVSS 4.3Proof of conceptEPSS 2%phpkit · phpkitDec 31, 2004
- CVE-2005-269918Monitor
Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PH
MediumCVSS 4.6No exploitEPSS 0%phpkit · phpkitAug 26, 2005
- CVE-2004-187917Monitor
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum me
MediumCVSS 4.3No exploitEPSS 1%phpkit · phpkitDec 31, 2004