Skip to content
Noroxi

phpwebthings records

9 published records for vendor phpwebthings.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
7
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

9 records
  • CVE-2005-4226
    31Monitor

    Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute arbitrary SQL command

    HighCVSS 7.5Proof of conceptEPSS 3%

    phpwebthings · phpwebthingsDec 14, 2005

  • CVE-2005-4218
    31Monitor

    SQL injection vulnerability in forum.php in PHPWebThings 1.4 allows remote attackers to execute arbitrary SQL commands via the msg parameter

    HighCVSS 7.5Proof of conceptEPSS 2%

    phpwebthings · phpwebthingsDec 14, 2005

  • CVE-2005-3585
    31Monitor

    SQL injection vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL commands via the forum param

    HighCVSS 7.5No exploitEPSS 2%

    phpwebthings · phpwebthingsNov 16, 2005

  • CVE-2009-2147
    31Monitor

    SQL injection vulnerability in fdown.php in phpWebThings 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the

    HighCVSS 7.5Proof of conceptEPSS 2%

    phpwebthings · phpwebthingsJun 22, 2009

  • CVE-2005-3676
    30Monitor

    SQL injection vulnerability in download.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL commands via the file par

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpwebthings · phpwebthingsNov 18, 2005

  • CVE-2006-6042
    29Monitor

    PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 and earlier, when register_globals is enabled, allows remot

    MediumCVSS 6.8Proof of conceptEPSS 6%

    phpwebthings · phpwebthingsNov 21, 2006

  • CVE-2007-3141
    28Monitor

    PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 allows remote attackers to execute arbitrary PHP code via a

    MediumCVSS 6.8Proof of conceptEPSS 2%

    phpwebthings · phpwebthingsJun 11, 2007

  • CVE-2009-2081
    18Monitor

    Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers

    MediumCVSS 4.3Proof of conceptEPSS 3%

    phpwebthings · phpwebthingsJun 16, 2009

  • CVE-2005-3584
    17Monitor

    Cross-site scripting (XSS) vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to inject arbitrary web script or HTML v

    MediumCVSS 4.3Proof of conceptEPSS 1%

    phpwebthings · phpwebthingsNov 16, 2005