Skip to content
Noroxi

phpx records

12 published records for vendor phpx.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
7
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    12 records
    • PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another

      CriticalCVSS 10.0Proof of conceptEPSS 5%

      phpx · phpxNov 23, 2004

    • CVE-2007-1550
      31Monitor

      Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) c

      HighCVSS 7.5Proof of conceptEPSS 2%

      phpx · phpxMar 20, 2007

    • CVE-2005-3968
      31Monitor

      SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass auth

      HighCVSS 7.5Proof of conceptEPSS 2%

      phpx · phpxDec 3, 2005

    • CVE-2008-3489
      30Monitor

      SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers to execute arbitrar

      HighCVSS 7.5Proof of conceptEPSS 1%

      phpx · phpxAug 6, 2008

    • CVE-2004-0248
      27Monitor

      Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbit

      MediumCVSS 6.8No exploitEPSS 1%

      phpx · phpxNov 23, 2004

    • CVE-2007-1549
      27Monitor

      Unrestricted file upload vulnerability in gallery.php in phpx 3.5.15 allows remote attackers to upload and execute arbitrary PHP scripts via

      MediumCVSS 6.8No exploitEPSS 1%

      phpx · phpxMar 20, 2007

    • CVE-2008-5000
      27Monitor

      SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows remote attackers to exe

      MediumCVSS 6.8Proof of conceptEPSS 1%

      phpx · phpxNov 10, 2008

    • CVE-2004-2364
      23Monitor

      Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs tha

      MediumCVSS 5.0Proof of conceptEPSS 11%

      phpx · phpxDec 31, 2004

    • CVE-2004-2362
      21Monitor

      PHPX 3.2.6 and earlier allows remote attackers to obtain the physical path of PHPX via a null or invalid value in the limit parameter, which

      MediumCVSS 5.0No exploitEPSS 2%

      phpx · phpxDec 31, 2004

    • CVE-2004-2363
      18Monitor

      Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers t

      MediumCVSS 4.3Proof of conceptEPSS 2%

      phpx · phpxDec 31, 2004

    • CVE-2006-0933
      18Monitor

      Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI i

      MediumCVSS 4.3Proof of conceptEPSS 2%

      phpx · phpxFeb 28, 2006

    • CVE-2007-1551
      17Monitor

      Multiple cross-site scripting (XSS) vulnerabilities in phpx 3.5.15 allow remote attackers to inject arbitrary web script or HTML via (1) the

      MediumCVSS 4.3No exploitEPSS 2%

      phpx · phpxMar 20, 2007