phpwind records
5 published records for vendor phpwind.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2006-7101Proof of concept | SQL injection vulnerability in admin.php in PHPWind 5.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Admiphpwind · phpwind | High7.5 | — | 1.0% | Mar 3, 2007 |
28Monitor | CVE-2019-6691No exploit | phpwind 9.0.2.170426 UTF8 allows SQL Injection via the admin.php?m=backup&c=backup&a=doback tabledb[] parameter, related to the "--backup daphpwind · phpwind · CWE-89 | High7.2 | — | 1.1% | Jan 23, 2019 |
24Monitor | CVE-2015-4134No exploit | Open redirect vulnerability in goto.php in phpwind 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishingphpwind · phpwind | Medium5.8 | — | 2.1% | May 28, 2015 |
24Monitor | CVE-2019-13472No exploit | PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file.phpwind · phpwind · CWE-79 | Medium6.1 | — | 0.8% | Jul 9, 2019 |
18Monitor | CVE-2015-4135No exploit | Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the uphpwind · phpwind · CWE-79 | Medium4.3 | — | 1.9% | May 28, 2015 |
- CVE-2006-710130Monitor
SQL injection vulnerability in admin.php in PHPWind 5.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Admi
HighCVSS 7.5Proof of conceptEPSS 1%phpwind · phpwindMar 3, 2007
- CVE-2019-669128Monitor
phpwind 9.0.2.170426 UTF8 allows SQL Injection via the admin.php?m=backup&c=backup&a=doback tabledb[] parameter, related to the "--backup da
HighCVSS 7.2No exploitEPSS 1%phpwind · phpwindJan 23, 2019
- CVE-2015-413424Monitor
Open redirect vulnerability in goto.php in phpwind 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing
MediumCVSS 5.8No exploitEPSS 2%phpwind · phpwindMay 28, 2015
- CVE-2019-1347224Monitor
PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file.
MediumCVSS 6.1No exploitEPSS 1%phpwind · phpwindJul 9, 2019
- CVE-2015-413518Monitor
Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the u
MediumCVSS 4.3No exploitEPSS 2%phpwind · phpwindMay 28, 2015