Skip to content
Noroxi

phprank records

4 published records for vendor phprank.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    Attack profile

    All records

    4 records
    • CVE-2002-1952
      30Monitor

      phpRank 1.8 does not properly check the return codes for MySQL operations when authenticating users, which could allow remote attackers to a

      HighCVSS 7.5No exploitEPSS 2%

      phprank · phprankDec 31, 2002

    • CVE-2002-1800
      30Monitor

      phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote attackers to retrieve

      HighCVSS 7.5No exploitEPSS 1%

      phprank · phprankDec 31, 2002

    • CVE-2002-1799
      18Monitor

      Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) email par

      MediumCVSS 4.3Proof of conceptEPSS 4%

      phprank · phprankDec 31, 2002

    • CVE-2002-1950
      18Monitor

      Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email

      MediumCVSS 4.3No exploitEPSS 2%

      phprank · phprankDec 31, 2002