Skip to content
Noroxi

phpoutsourcing records

23 published records for vendor phpoutsourcing.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
7
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    All records

    23 records
    • CVE-2006-0881
      32Monitor

      Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow re

      HighCVSS 7.5Proof of conceptEPSS 8%

      phpoutsourcing · noahs classifiedsFeb 24, 2006

    • CVE-2005-2651
      32Monitor

      gorum/prod.php in Zorum 3.5 allows remote attackers to execute arbitrary code via shell metacharacters in the argv parameter.

      HighCVSS 7.5Proof of conceptEPSS 5%

      phpoutsourcing · zorumAug 23, 2005

    • CVE-2008-5199
      31Monitor

      PHP remote file inclusion vulnerability in include.php in PHPOutsourcing IdeaBox (aka IdeBox) 1.1 allows remote attackers to execute arbitra

      HighCVSS 7.5Proof of conceptEPSS 3%

      phpoutsourcing · ideaboxNov 21, 2008

    • CVE-2006-5431
      31Monitor

      PHP remote file inclusion vulnerability in gorum/dbproperty.php in PHPOutsourcing Zorum 3.5 and earlier allows remote attackers to execute a

      HighCVSS 7.5Proof of conceptEPSS 2%

      phpoutsourcing · zorumOct 20, 2006

    • CVE-2005-0676
      30Monitor

      index.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capabilit

      HighCVSS 7.5No exploitEPSS 1%

      phpoutsourcing · zorumMay 4, 2005

    • CVE-2006-0879
      30Monitor

      SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspe

      HighCVSS 7.5Proof of conceptEPSS 1%

      phpoutsourcing · noahs classifiedsFeb 24, 2006

    • CVE-2006-3332
      30Monitor

      SQL injection vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to execute arbitrary SQL commands via the (1) offset, (2

      HighCVSS 7.5No exploitEPSS 1%

      phpoutsourcing · zorumJun 30, 2006

    • CVE-2005-2979
      30Monitor

      SQL injection vulnerability in index.php in phpoutsourcing Noah's classifieds allows remote attackers to execute arbitrary SQL commands via

      HighCVSS 7.5Proof of conceptEPSS 1%

      phpoutsourcing · noahs classifiedsSep 19, 2005

    • CVE-2005-4619
      30Monitor

      SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL comm

      HighCVSS 7.5Proof of conceptEPSS 1%

      phpoutsourcing · zorumDec 31, 2005

    • CVE-2006-1331
      27Monitor

      Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 and earlier allow remote attackers to inject arbi

      MediumCVSS 6.8No exploitEPSS 1%

      phpoutsourcing · noahs classifiedsMar 20, 2006

    • CVE-2006-5293
      27Monitor

      Cross-site scripting (XSS) vulnerability in index.php in PhpOutsourcing Noah's Classifieds 1.3 and earlier allows remote attackers to inject

      MediumCVSS 6.8No exploitEPSS 1%

      phpoutsourcing · noahs classifiedsOct 16, 2006

    • CVE-2006-1332
      25Monitor

      Noah's Classifieds 1.3 and earlier allows remote attackers to obtain sensitive information via an invalid list parameter in the showdetails

      MediumCVSS 6.4No exploitEPSS 2%

      phpoutsourcing · noahs classifiedsMar 20, 2006

    • CVE-2003-1089
      21Monitor

      index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the pa

      MediumCVSS 5.0Proof of conceptEPSS 3%

      phpoutsourcing · zorumDec 31, 2003

    • CVE-2006-0882
      21Monitor

      Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary local files via the

      MediumCVSS 5.0Proof of conceptEPSS 3%

      phpoutsourcing · noahs classifiedsFeb 24, 2006

    • CVE-2005-2652
      20Monitor

      Zorum 3.5 allows remote attackers to obtain the full installation path via direct requests to (1) gorum/notification.php, (2) user.php, (3)

      MediumCVSS 5.0No exploitEPSS 2%

      phpoutsourcing · zorumAug 23, 2005

    • CVE-2006-0878
      20Monitor

      Noah's Classifieds 1.3 allows remote attackers to obtain the installation path via a direct request to include files, as demonstrated by cla

      MediumCVSS 5.0No exploitEPSS 2%

      phpoutsourcing · noahs classifiedsFeb 24, 2006

    • CVE-2005-0677
      20Monitor

      index.php for Zorum 3.5 allows remote attackers to perform certain actions as other users by modifying the id parameter.

      MediumCVSS 5.0No exploitEPSS 1%

      phpoutsourcing · zorumMay 2, 2005

    • CVE-2006-0880
      18Monitor

      Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web sc

      MediumCVSS 4.3Proof of conceptEPSS 2%

      phpoutsourcing · noahs classifiedsFeb 24, 2006

    • CVE-2005-2980
      18Monitor

      Cross-site scripting (XSS) vulnerability in index.php in phpoutsourcing Noah's classifieds 1.3 allows remote attackers to inject arbitrary w

      MediumCVSS 4.3Proof of conceptEPSS 2%

      phpoutsourcing · noahs classifiedsSep 19, 2005

    • CVE-2003-1088
      18Monitor

      Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary web script or HTML v

      MediumCVSS 4.3Proof of conceptEPSS 2%

      phpoutsourcing · zorumAug 11, 2003

    • CVE-2005-0675
      17Monitor

      Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.5 allows remote attackers to inject arbitrary web script or HTML via the (

      MediumCVSS 4.3No exploitEPSS 1%

      phpoutsourcing · zorumMay 2, 2005

    • CVE-2002-2350
      17Monitor

      Cross-site scripting (XSS) vulnerability in z_user_show.php in dbtreelistproperty_method.php in Zorum 2.4 allows remote attackers to inject

      MediumCVSS 4.3No exploitEPSS 1%

      phpoutsourcing · zorumDec 31, 2002

    • CVE-2006-3333
      10Monitor

      Cross-site scripting (XSS) vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to inject web script or HTML via the multip

      LowCVSS 2.6No exploitEPSS 1%

      phpoutsourcing · zorumJun 30, 2006