playsms records
14 published records for vendor playsms.
Researcher profile
- Entered KEV
- 1 · 7.1%
- Weaponized
- 3 · 21.4%
- Pre-auth RCE
- 6
- With a fix record
- 0%
- Median publish → KEV
- 637 days
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
- CWE-697 Incorrect Comparison1
- CWE-384 Session Fixation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2020-8644Weaponized | PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.playsms · playsms · CWE-94 | Critical9.8 | KEV | 86.7% | Feb 5, 2020 |
62This week | CVE-2017-9101Weaponized | import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header aplaysms · playsms · CWE-434 | Critical9.8 | — | 76.7% | May 21, 2017 |
54Plan | CVE-2017-9080Weaponized | PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed.playsms · playsms · CWE-434 | High8.8 | — | 62.3% | May 19, 2017 |
40Plan | CVE-2021-40373Proof of concept | playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executplaysms · playsms · CWE-94 | Critical9.8 | — | 4.7% | Sep 10, 2021 |
39Monitor | CVE-2022-47034No exploit | A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.playsms · playsms · CWE-697 | Critical9.8 | — | 0.8% | Feb 13, 2023 |
33Monitor | CVE-2009-0103Proof of concept | Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1playsms · playsms · CWE-94 | High7.5 | — | 10.1% | Jan 9, 2009 |
32Monitor | CVE-2008-5881Proof of concept | Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary local files via directplaysms · playsms · CWE-22 | High7.5 | — | 7.3% | Jan 9, 2009 |
30Monitor | CVE-2004-2263Proof of concept | SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statementsplaysms · playsms | High7.5 | — | 1.4% | Dec 31, 2004 |
26Monitor | CVE-2020-15018No exploit | playSMS through 1.4.3 is vulnerable to session fixation.playsms · playsms · CWE-384 | Medium6.5 | — | 0.9% | Jun 24, 2020 |
25Monitor | CVE-2024-8880No exploit | playSMS Template index.php code injectionplaysms · playsms · CWE-94 | Medium6.3 | — | 0.7% | Sep 15, 2024 |
20Monitor | CVE-2024-6469No exploit | playSMS Template injectionplaysms · playsms · CWE-74 | Medium5.1 | — | 0.7% | Jul 3, 2024 |
20Monitor | CVE-2024-6470No exploit | playSMS Template injectionplaysms · playsms · CWE-74 | Medium5.1 | — | 0.4% | Jul 3, 2024 |
20Monitor | CVE-2024-6251No exploit | playSMS New Phonebook cross site scriptingplaysms · playsms · CWE-80 | Medium5.1 | — | 0.4% | Jun 22, 2024 |
18Monitor | CVE-2005-4432Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8 allows remote attackers to inject arbitrary web script or HTML via the playsms · playsms | Medium4.3 | — | 2.0% | Dec 20, 2005 |
- CVE-2020-864495Now
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
CriticalCVSS 9.8KEVWeaponizedEPSS 87%playsms · playsmsFeb 5, 2020
- CVE-2017-910162This week
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header a
CriticalCVSS 9.8WeaponizedEPSS 77%playsms · playsmsMay 21, 2017
- CVE-2017-908054Plan
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed.
HighCVSS 8.8WeaponizedEPSS 62%playsms · playsmsMay 19, 2017
- CVE-2021-4037340Plan
playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then execut
CriticalCVSS 9.8Proof of conceptEPSS 5%playsms · playsmsSep 10, 2021
- CVE-2022-4703439Monitor
A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.
CriticalCVSS 9.8No exploitEPSS 1%playsms · playsmsFeb 13, 2023
- CVE-2009-010333Monitor
Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1
HighCVSS 7.5Proof of conceptEPSS 10%playsms · playsmsJan 9, 2009
- CVE-2008-588132Monitor
Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary local files via direct
HighCVSS 7.5Proof of conceptEPSS 7%playsms · playsmsJan 9, 2009
- CVE-2004-226330Monitor
SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements
HighCVSS 7.5Proof of conceptEPSS 1%playsms · playsmsDec 31, 2004
- CVE-2020-1501826Monitor
playSMS through 1.4.3 is vulnerable to session fixation.
MediumCVSS 6.5No exploitEPSS 1%playsms · playsmsJun 24, 2020
- CVE-2024-888025Monitor
playSMS Template index.php code injection
MediumCVSS 6.3No exploitEPSS 1%playsms · playsmsSep 15, 2024
- CVE-2024-646920Monitor
playSMS Template injection
MediumCVSS 5.1No exploitEPSS 1%playsms · playsmsJul 3, 2024
- CVE-2024-647020Monitor
playSMS Template injection
MediumCVSS 5.1No exploitEPSS 0%playsms · playsmsJul 3, 2024
- CVE-2024-625120Monitor
playSMS New Phonebook cross site scripting
MediumCVSS 5.1No exploitEPSS 0%playsms · playsmsJun 22, 2024
- CVE-2005-443218Monitor
Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8 allows remote attackers to inject arbitrary web script or HTML via the
MediumCVSS 4.3Proof of conceptEPSS 2%playsms · playsmsDec 20, 2005