Skip to content
Noroxi

phpkit records

20 published records for vendor phpkit.

All records

20 records
  • PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the

    HighCVSS 8.8No exploitEPSS 2%

    phpkit · phpkitMay 24, 2019

  • CVE-2005-2683
    31Monitor

    Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter

    HighCVSS 7.5Proof of conceptEPSS 2%

    phpkit · phpkitAug 23, 2005

  • CVE-2005-3553
    31Monitor

    Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL command

    HighCVSS 7.5No exploitEPSS 2%

    phpkit · phpkitNov 16, 2005

  • CVE-2006-7115
    30Monitor

    SQL injection vulnerability in PHPKit 1.6.1 RC2 allows remote attackers to inject arbitrary SQL commands via the catid parameter to include.

    HighCVSS 7.5No exploitEPSS 1%

    phpkit · phpkitMar 5, 2007

  • CVE-2004-1538
    30Monitor

    SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the

    HighCVSS 7.5No exploitEPSS 1%

    phpkit · phpkitDec 31, 2004

  • CVE-2007-6134
    30Monitor

    SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via the

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpkit · phpkitNov 27, 2007

  • CVE-2007-0179
    30Monitor

    SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parame

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpkit · phpkitJan 10, 2007

  • CVE-2003-1187
    28Monitor

    Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script o

    MediumCVSS 6.8Proof of conceptEPSS 4%

    phpkit · phpkitNov 2, 2003

  • CVE-2005-4424
    27Monitor

    Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a

    MediumCVSS 6.5No exploitEPSS 2%

    phpkit · phpkitDec 20, 2005

  • CVE-2006-1507
    27Monitor

    Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error param

    MediumCVSS 6.8No exploitEPSS 1%

    phpkit · phpkitMar 29, 2006

  • CVE-2008-7193
    27Monitor

    PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by r

    MediumCVSS 6.8No exploitEPSS 1%

    phpkit · phpkitSep 9, 2009

  • CVE-2006-0785
    25Monitor

    Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute ar

    MediumCVSS 6.4No exploitEPSS 2%

    phpkit · phpkitFeb 19, 2006

  • CVE-2006-1773
    25Monitor

    SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands v

    MediumCVSS 6.4Proof of conceptEPSS 1%

    phpkit · phpkitApr 13, 2006

  • CVE-2005-3554
    21Monitor

    Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote

    MediumCVSS 5.1No exploitEPSS 3%

    phpkit · phpkitNov 16, 2005

  • CVE-2006-0786
    21Monitor

    Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attacke

    MediumCVSS 5.1Proof of conceptEPSS 2%

    phpkit · phpkitFeb 19, 2006

  • CVE-2005-3552
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or

    MediumCVSS 4.3No exploitEPSS 2%

    phpkit · phpkitNov 16, 2005

  • CVE-2015-1052
    18Monitor

    Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT 1.6.6 (Build 160014) allows remote attackers to inject arbitrary web

    MediumCVSS 4.3No exploitEPSS 2%

    phpkit · phpkitJan 15, 2015

  • CVE-2004-1537
    18Monitor

    Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script

    MediumCVSS 4.3Proof of conceptEPSS 2%

    phpkit · phpkitDec 31, 2004

  • CVE-2005-2699
    18Monitor

    Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PH

    MediumCVSS 4.6No exploitEPSS 0%

    phpkit · phpkitAug 26, 2005

  • CVE-2004-1879
    17Monitor

    Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum me

    MediumCVSS 4.3No exploitEPSS 1%

    phpkit · phpkitDec 31, 2004