pwsphp records
8 published records for vendor pwsphp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2005-1511No exploit | PwsPHP 1.2.2 allows remote attackers to bypass authentication and post arbitrary comments via the Pseudo cookie.pwsphp · pwsphp | High7.5 | — | 1.7% | May 11, 2005 |
30Monitor | CVE-2005-1512No exploit | The Admin panel in PwsPHP 1.2.2 does not properly verify uploaded picture files, which allows remote attackers to upload and possibly executpwsphp · pwsphp | High7.5 | — | 1.5% | May 11, 2005 |
30Monitor | CVE-2005-1510No exploit | PwsPHP 1.2.2 allows remote attackers to obtain sensitive information via a direct request to the admin directory, which reveals the path in pwsphp · pwsphp | High7.5 | — | 1.5% | May 11, 2005 |
30Monitor | CVE-2006-0943Proof of concept | SQL injection vulnerability in the sondages module in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands vipwsphp · pwsphp | High7.5 | — | 1.3% | Feb 28, 2006 |
30Monitor | CVE-2005-1509No exploit | SQL injection vulnerability in profil.php in PwsPHP 1.2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.pwsphp · pwsphp | High7.5 | — | 1.2% | May 11, 2005 |
30Monitor | CVE-2006-0668Proof of concept | SQL injection vulnerability in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter, pospwsphp · pwsphp | High7.5 | — | 1.2% | Feb 13, 2006 |
30Monitor | CVE-2006-0942Proof of concept | SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL cpwsphp · pwsphp | High7.5 | — | 1.1% | Feb 28, 2006 |
28Monitor | CVE-2005-1508No exploit | Multiple cross-site scripting (XSS) vulnerabilities in PwsPHP 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1pwsphp · pwsphp | Medium6.8 | — | 1.9% | May 11, 2005 |
- CVE-2005-151131Monitor
PwsPHP 1.2.2 allows remote attackers to bypass authentication and post arbitrary comments via the Pseudo cookie.
HighCVSS 7.5No exploitEPSS 2%pwsphp · pwsphpMay 11, 2005
- CVE-2005-151230Monitor
The Admin panel in PwsPHP 1.2.2 does not properly verify uploaded picture files, which allows remote attackers to upload and possibly execut
HighCVSS 7.5No exploitEPSS 2%pwsphp · pwsphpMay 11, 2005
- CVE-2005-151030Monitor
PwsPHP 1.2.2 allows remote attackers to obtain sensitive information via a direct request to the admin directory, which reveals the path in
HighCVSS 7.5No exploitEPSS 2%pwsphp · pwsphpMay 11, 2005
- CVE-2006-094330Monitor
SQL injection vulnerability in the sondages module in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands vi
HighCVSS 7.5Proof of conceptEPSS 1%pwsphp · pwsphpFeb 28, 2006
- CVE-2005-150930Monitor
SQL injection vulnerability in profil.php in PwsPHP 1.2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
HighCVSS 7.5No exploitEPSS 1%pwsphp · pwsphpMay 11, 2005
- CVE-2006-066830Monitor
SQL injection vulnerability in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter, pos
HighCVSS 7.5Proof of conceptEPSS 1%pwsphp · pwsphpFeb 13, 2006
- CVE-2006-094230Monitor
SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL c
HighCVSS 7.5Proof of conceptEPSS 1%pwsphp · pwsphpFeb 28, 2006
- CVE-2005-150828Monitor
Multiple cross-site scripting (XSS) vulnerabilities in PwsPHP 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1
MediumCVSS 6.8No exploitEPSS 2%pwsphp · pwsphpMay 11, 2005