phpwebsite records
20 published records for vendor phpwebsite.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 12
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-134 Use of Externally-Controlled Format String1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2002-1135Proof of concept | modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_pphpwebsite · phpwebsite | High7.5 | — | 6.6% | Oct 4, 2002 |
31Monitor | CVE-2006-1819No exploit | Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to includphpwebsite · phpwebsite | High7.5 | — | 3.9% | Apr 18, 2006 |
31Monitor | CVE-2006-5234Proof of concept | Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in thphpwebsite · phpwebsite | High7.5 | — | 2.8% | Oct 10, 2006 |
31Monitor | CVE-2005-0565No exploit | The Announce module in phpWebSite 0.10.0 and earlier allows remote attackers to execute arbitrary PHP code by setting the Image field to refphpwebsite · phpwebsite | High7.5 | — | 1.7% | May 2, 2005 |
31Monitor | CVE-2003-0735Proof of concept | SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries,phpwebsite · phpwebsite | High7.5 | — | 1.7% | Oct 20, 2003 |
31Monitor | CVE-2003-0738No exploit | The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.phpwebsite · phpwebsite · CWE-134 | High7.8 | — | 1.5% | Oct 20, 2003 |
30Monitor | CVE-2004-2322No exploit | SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attackers to execute arbitrphpwebsite · phpwebsite | High7.5 | — | 1.5% | Dec 31, 2004 |
30Monitor | CVE-2004-1654No exploit | SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commanphpwebsite · phpwebsite | High7.5 | — | 1.3% | Sep 1, 2004 |
30Monitor | CVE-2006-0973Proof of concept | SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote attackers to execute aphpwebsite · phpwebsite | High7.5 | — | 1.3% | Mar 3, 2006 |
30Monitor | CVE-2006-1330Proof of concept | Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid pphpwebsite · phpwebsite · CWE-89 | High7.5 | — | 1.3% | Mar 20, 2006 |
30Monitor | CVE-2005-4792Proof of concept | SQL injection vulnerability in index.php in Appalachian State University phpWebSite 0.10.1 and earlier allows remote attackers to execute arphpwebsite · phpwebsite | High7.5 | — | 1.1% | Dec 31, 2005 |
28Monitor | CVE-2003-0736Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script vphpwebsite · phpwebsite | Medium6.8 | — | 2.7% | Oct 20, 2003 |
21Monitor | CVE-2005-0572No exploit | index.php in phpWebSite 0.10.0 and earlier allows remote attackers to obtain sensitive information via an invalid SEA_search_module parametephpwebsite · phpwebsite | Medium5.0 | — | 2.1% | May 2, 2005 |
20Monitor | CVE-2004-1516No exploit | CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modifyphpwebsite · phpwebsite | Medium5.0 | — | 1.6% | Dec 31, 2004 |
20Monitor | CVE-2003-0737No exploit | The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, wphpwebsite · phpwebsite | Medium5.0 | — | 1.3% | Oct 20, 2003 |
18Monitor | CVE-2004-1655Proof of concept | Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML viphpwebsite · phpwebsite | Medium4.3 | — | 2.2% | Sep 1, 2004 |
18Monitor | CVE-2002-2178Proof of concept | Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript phpwebsite · phpwebsite | Medium4.3 | — | 1.7% | Dec 31, 2002 |
18Monitor | CVE-2008-0092Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote atphpwebsite · phpwebsite · CWE-79 | Medium4.3 | — | 1.7% | Jan 3, 2008 |
17Monitor | CVE-2002-1807No exploit | Cross-site scripting (XSS) vulnerability in phpWebSite 0.8.3 allows remote attackers to inject arbitrary web script or HTML via Javascript iphpwebsite · phpwebsite | Medium4.3 | — | 1.2% | Dec 31, 2002 |
17Monitor | CVE-2011-4265No exploit | Cross-site scripting (XSS) vulnerability in phpWebSite before 1.0.0 allows remote attackers to inject arbitrary web script or HTML via unspephpwebsite · phpwebsite · CWE-79 | Medium4.3 | — | 0.8% | Dec 8, 2011 |
- CVE-2002-113532Monitor
modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_p
HighCVSS 7.5Proof of conceptEPSS 7%phpwebsite · phpwebsiteOct 4, 2002
- CVE-2006-181931Monitor
Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to includ
HighCVSS 7.5No exploitEPSS 4%phpwebsite · phpwebsiteApr 18, 2006
- CVE-2006-523431Monitor
Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in th
HighCVSS 7.5Proof of conceptEPSS 3%phpwebsite · phpwebsiteOct 10, 2006
- CVE-2005-056531Monitor
The Announce module in phpWebSite 0.10.0 and earlier allows remote attackers to execute arbitrary PHP code by setting the Image field to ref
HighCVSS 7.5No exploitEPSS 2%phpwebsite · phpwebsiteMay 2, 2005
- CVE-2003-073531Monitor
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries,
HighCVSS 7.5Proof of conceptEPSS 2%phpwebsite · phpwebsiteOct 20, 2003
- CVE-2003-073831Monitor
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.
HighCVSS 7.8No exploitEPSS 1%phpwebsite · phpwebsiteOct 20, 2003
- CVE-2004-232230Monitor
SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attackers to execute arbitr
HighCVSS 7.5No exploitEPSS 2%phpwebsite · phpwebsiteDec 31, 2004
- CVE-2004-165430Monitor
SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL comman
HighCVSS 7.5No exploitEPSS 1%phpwebsite · phpwebsiteSep 1, 2004
- CVE-2006-097330Monitor
SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote attackers to execute a
HighCVSS 7.5Proof of conceptEPSS 1%phpwebsite · phpwebsiteMar 3, 2006
- CVE-2006-133030Monitor
Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid p
HighCVSS 7.5Proof of conceptEPSS 1%phpwebsite · phpwebsiteMar 20, 2006
- CVE-2005-479230Monitor
SQL injection vulnerability in index.php in Appalachian State University phpWebSite 0.10.1 and earlier allows remote attackers to execute ar
HighCVSS 7.5Proof of conceptEPSS 1%phpwebsite · phpwebsiteDec 31, 2005
- CVE-2003-073628Monitor
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script v
MediumCVSS 6.8Proof of conceptEPSS 3%phpwebsite · phpwebsiteOct 20, 2003
- CVE-2005-057221Monitor
index.php in phpWebSite 0.10.0 and earlier allows remote attackers to obtain sensitive information via an invalid SEA_search_module paramete
MediumCVSS 5.0No exploitEPSS 2%phpwebsite · phpwebsiteMay 2, 2005
- CVE-2004-151620Monitor
CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify
MediumCVSS 5.0No exploitEPSS 2%phpwebsite · phpwebsiteDec 31, 2004
- CVE-2003-073720Monitor
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, w
MediumCVSS 5.0No exploitEPSS 1%phpwebsite · phpwebsiteOct 20, 2003
- CVE-2004-165518Monitor
Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML vi
MediumCVSS 4.3Proof of conceptEPSS 2%phpwebsite · phpwebsiteSep 1, 2004
- CVE-2002-217818Monitor
Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript
MediumCVSS 4.3Proof of conceptEPSS 2%phpwebsite · phpwebsiteDec 31, 2002
- CVE-2008-009218Monitor
Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote at
MediumCVSS 4.3Proof of conceptEPSS 2%phpwebsite · phpwebsiteJan 3, 2008
- CVE-2002-180717Monitor
Cross-site scripting (XSS) vulnerability in phpWebSite 0.8.3 allows remote attackers to inject arbitrary web script or HTML via Javascript i
MediumCVSS 4.3No exploitEPSS 1%phpwebsite · phpwebsiteDec 31, 2002
- CVE-2011-426517Monitor
Cross-site scripting (XSS) vulnerability in phpWebSite before 1.0.0 allows remote attackers to inject arbitrary web script or HTML via unspe
MediumCVSS 4.3No exploitEPSS 1%phpwebsite · phpwebsiteDec 8, 2011