phpslash records
4 published records for vendor phpslash.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2009-0517Proof of concept | Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fielphpslash · phpslash · CWE-94 | Critical10.0 | — | 48.9% | Feb 10, 2009 |
41Plan | CVE-2005-2257No exploit | The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_phpslash · phpslash | Critical10.0 | — | 2.8% | Jul 13, 2005 |
30Monitor | CVE-2005-4479Proof of concept | SQL injection vulnerability in article.php in phpSlash 0.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the sphpslash · phpslash | High7.5 | — | 1.2% | Dec 22, 2005 |
21Monitor | CVE-2001-1334Proof of concept | Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating phpslash · phpslash | Medium5.0 | — | 3.1% | May 19, 2002 |
- CVE-2009-051755Plan
Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fiel
CriticalCVSS 10.0Proof of conceptEPSS 49%phpslash · phpslashFeb 10, 2009
- CVE-2005-225741Plan
The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_
CriticalCVSS 10.0No exploitEPSS 3%phpslash · phpslashJul 13, 2005
- CVE-2005-447930Monitor
SQL injection vulnerability in article.php in phpSlash 0.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s
HighCVSS 7.5Proof of conceptEPSS 1%phpslash · phpslashDec 22, 2005
- CVE-2001-133421Monitor
Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating
MediumCVSS 5.0Proof of conceptEPSS 3%phpslash · phpslashMay 19, 2002