Skip to content
Noroxi

pwsphp records

8 published records for vendor pwsphp.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
5
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

      The weakness classes this vendor ships most often: where to look.

      CWE

      All records

      8 records
      • CVE-2005-1511
        31Monitor

        PwsPHP 1.2.2 allows remote attackers to bypass authentication and post arbitrary comments via the Pseudo cookie.

        HighCVSS 7.5No exploitEPSS 2%

        pwsphp · pwsphpMay 11, 2005

      • CVE-2005-1512
        30Monitor

        The Admin panel in PwsPHP 1.2.2 does not properly verify uploaded picture files, which allows remote attackers to upload and possibly execut

        HighCVSS 7.5No exploitEPSS 2%

        pwsphp · pwsphpMay 11, 2005

      • CVE-2005-1510
        30Monitor

        PwsPHP 1.2.2 allows remote attackers to obtain sensitive information via a direct request to the admin directory, which reveals the path in

        HighCVSS 7.5No exploitEPSS 2%

        pwsphp · pwsphpMay 11, 2005

      • CVE-2006-0943
        30Monitor

        SQL injection vulnerability in the sondages module in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands vi

        HighCVSS 7.5Proof of conceptEPSS 1%

        pwsphp · pwsphpFeb 28, 2006

      • CVE-2005-1509
        30Monitor

        SQL injection vulnerability in profil.php in PwsPHP 1.2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

        HighCVSS 7.5No exploitEPSS 1%

        pwsphp · pwsphpMay 11, 2005

      • CVE-2006-0668
        30Monitor

        SQL injection vulnerability in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter, pos

        HighCVSS 7.5Proof of conceptEPSS 1%

        pwsphp · pwsphpFeb 13, 2006

      • CVE-2006-0942
        30Monitor

        SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL c

        HighCVSS 7.5Proof of conceptEPSS 1%

        pwsphp · pwsphpFeb 28, 2006

      • CVE-2005-1508
        28Monitor

        Multiple cross-site scripting (XSS) vulnerabilities in PwsPHP 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1

        MediumCVSS 6.8No exploitEPSS 2%

        pwsphp · pwsphpMay 11, 2005