Skip to content
Noroxi

playsms records

14 published records for vendor playsms.

All records

14 records
  • PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

    CriticalCVSS 9.8KEVWeaponizedEPSS 87%

    playsms · playsmsFeb 5, 2020

  • CVE-2017-9101
    62This week

    import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header a

    CriticalCVSS 9.8WeaponizedEPSS 77%

    playsms · playsmsMay 21, 2017

  • PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed.

    HighCVSS 8.8WeaponizedEPSS 62%

    playsms · playsmsMay 19, 2017

  • playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then execut

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    playsms · playsmsSep 10, 2021

  • A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.

    CriticalCVSS 9.8No exploitEPSS 1%

    playsms · playsmsFeb 13, 2023

  • CVE-2009-0103
    33Monitor

    Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1

    HighCVSS 7.5Proof of conceptEPSS 10%

    playsms · playsmsJan 9, 2009

  • CVE-2008-5881
    32Monitor

    Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary local files via direct

    HighCVSS 7.5Proof of conceptEPSS 7%

    playsms · playsmsJan 9, 2009

  • CVE-2004-2263
    30Monitor

    SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements

    HighCVSS 7.5Proof of conceptEPSS 1%

    playsms · playsmsDec 31, 2004

  • playSMS through 1.4.3 is vulnerable to session fixation.

    MediumCVSS 6.5No exploitEPSS 1%

    playsms · playsmsJun 24, 2020

  • CVE-2024-8880
    25Monitor

    playSMS Template index.php code injection

    MediumCVSS 6.3No exploitEPSS 1%

    playsms · playsmsSep 15, 2024

  • CVE-2024-6469
    20Monitor

    playSMS Template injection

    MediumCVSS 5.1No exploitEPSS 1%

    playsms · playsmsJul 3, 2024

  • CVE-2024-6470
    20Monitor

    playSMS Template injection

    MediumCVSS 5.1No exploitEPSS 0%

    playsms · playsmsJul 3, 2024

  • CVE-2024-6251
    20Monitor

    playSMS New Phonebook cross site scripting

    MediumCVSS 5.1No exploitEPSS 0%

    playsms · playsmsJun 22, 2024

  • CVE-2005-4432
    18Monitor

    Cross-site scripting (XSS) vulnerability in index.php in PlaySMS 0.8 allows remote attackers to inject arbitrary web script or HTML via the

    MediumCVSS 4.3Proof of conceptEPSS 2%

    playsms · playsmsDec 20, 2005