phpx records
12 published records for vendor phpx.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2004-0249Proof of concept | PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another phpx · phpx | Critical10.0 | — | 4.9% | Nov 23, 2004 |
31Monitor | CVE-2007-1550Proof of concept | Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) cphpx · phpx | High7.5 | — | 2.0% | Mar 20, 2007 |
31Monitor | CVE-2005-3968Proof of concept | SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass authphpx · phpx | High7.5 | — | 2.0% | Dec 3, 2005 |
30Monitor | CVE-2008-3489Proof of concept | SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers to execute arbitrarphpx · phpx · CWE-89 | High7.5 | — | 1.0% | Aug 6, 2008 |
27Monitor | CVE-2004-0248No exploit | Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbitphpx · phpx | Medium6.8 | — | 1.5% | Nov 23, 2004 |
27Monitor | CVE-2007-1549No exploit | Unrestricted file upload vulnerability in gallery.php in phpx 3.5.15 allows remote attackers to upload and execute arbitrary PHP scripts viaphpx · phpx | Medium6.8 | — | 1.2% | Mar 20, 2007 |
27Monitor | CVE-2008-5000Proof of concept | SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows remote attackers to exephpx · phpx · CWE-89 | Medium6.8 | — | 0.9% | Nov 10, 2008 |
23Monitor | CVE-2004-2364Proof of concept | Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs thaphpx · phpx | Medium5.0 | — | 10.7% | Dec 31, 2004 |
21Monitor | CVE-2004-2362No exploit | PHPX 3.2.6 and earlier allows remote attackers to obtain the physical path of PHPX via a null or invalid value in the limit parameter, whichphpx · phpx | Medium5.0 | — | 1.7% | Dec 31, 2004 |
18Monitor | CVE-2004-2363Proof of concept | Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers tphpx · phpx | Medium4.3 | — | 1.8% | Dec 31, 2004 |
18Monitor | CVE-2006-0933Proof of concept | Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI iphpx · phpx | Medium4.3 | — | 1.7% | Feb 28, 2006 |
17Monitor | CVE-2007-1551No exploit | Multiple cross-site scripting (XSS) vulnerabilities in phpx 3.5.15 allow remote attackers to inject arbitrary web script or HTML via (1) thephpx · phpx | Medium4.3 | — | 1.5% | Mar 20, 2007 |
- CVE-2004-024941Plan
PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another
CriticalCVSS 10.0Proof of conceptEPSS 5%phpx · phpxNov 23, 2004
- CVE-2007-155031Monitor
Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) c
HighCVSS 7.5Proof of conceptEPSS 2%phpx · phpxMar 20, 2007
- CVE-2005-396831Monitor
SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass auth
HighCVSS 7.5Proof of conceptEPSS 2%phpx · phpxDec 3, 2005
- CVE-2008-348930Monitor
SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers to execute arbitrar
HighCVSS 7.5Proof of conceptEPSS 1%phpx · phpxAug 6, 2008
- CVE-2004-024827Monitor
Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbit
MediumCVSS 6.8No exploitEPSS 1%phpx · phpxNov 23, 2004
- CVE-2007-154927Monitor
Unrestricted file upload vulnerability in gallery.php in phpx 3.5.15 allows remote attackers to upload and execute arbitrary PHP scripts via
MediumCVSS 6.8No exploitEPSS 1%phpx · phpxMar 20, 2007
- CVE-2008-500027Monitor
SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows remote attackers to exe
MediumCVSS 6.8Proof of conceptEPSS 1%phpx · phpxNov 10, 2008
- CVE-2004-236423Monitor
Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs tha
MediumCVSS 5.0Proof of conceptEPSS 11%phpx · phpxDec 31, 2004
- CVE-2004-236221Monitor
PHPX 3.2.6 and earlier allows remote attackers to obtain the physical path of PHPX via a null or invalid value in the limit parameter, which
MediumCVSS 5.0No exploitEPSS 2%phpx · phpxDec 31, 2004
- CVE-2004-236318Monitor
Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers t
MediumCVSS 4.3Proof of conceptEPSS 2%phpx · phpxDec 31, 2004
- CVE-2006-093318Monitor
Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI i
MediumCVSS 4.3Proof of conceptEPSS 2%phpx · phpxFeb 28, 2006
- CVE-2007-155117Monitor
Multiple cross-site scripting (XSS) vulnerabilities in phpx 3.5.15 allow remote attackers to inject arbitrary web script or HTML via (1) the
MediumCVSS 4.3No exploitEPSS 2%phpx · phpxMar 20, 2007