Skip to content
Noroxi

scriptphp records

9 published records for vendor scriptphp.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    9 records
    • CVE-2006-6478
      33Monitor

      Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parame

      HighCVSS 7.5Proof of conceptEPSS 11%

      scriptphp · annoncescripthpDec 11, 2006

    • CVE-2006-6521
      30Monitor

      SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0 allows remote attackers to execute arbitrary SQL commands via the aa

      HighCVSS 7.5Proof of conceptEPSS 1%

      scriptphp · messageriescripthpDec 13, 2006

    • CVE-2006-6519
      30Monitor

      SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows remote attackers to execute arbitrary SQL commands via the aa parameter.

      HighCVSS 7.5Proof of conceptEPSS 1%

      scriptphp · pronewsDec 13, 2006

    • CVE-2006-6520
      28Monitor

      Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML

      MediumCVSS 6.8Proof of conceptEPSS 2%

      scriptphp · messageriescripthpDec 13, 2006

    • CVE-2006-6479
      28Monitor

      Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via

      MediumCVSS 6.8Proof of conceptEPSS 2%

      scriptphp · annoncescripthpDec 11, 2006

    • CVE-2006-6518
      28Monitor

      Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1)

      MediumCVSS 6.8Proof of conceptEPSS 2%

      scriptphp · pronewsDec 13, 2006

    • CVE-2006-6580
      25Monitor

      admin/change.php in ProNews 1.5 does not check whether a user is permitted to change news items, which allows remote attackers to add or del

      MediumCVSS 6.4No exploitEPSS 1%

      scriptphp · pronewsDec 15, 2006

    • CVE-2006-6480
      20Monitor

      admin/admin_membre/fiche_membre.php in AnnonceScriptHP 2.0 allows remote attackers to obtain sensitive information via the idmembre paramete

      MediumCVSS 5.0No exploitEPSS 1%

      scriptphp · annoncescripthpDec 11, 2006

    • CVE-2008-2280
      17Monitor

      Cross-site scripting (XSS) vulnerability in admin/index.php in Script PHP PicEngine 1.0 allows remote attackers to inject arbitrary web scri

      MediumCVSS 4.3No exploitEPSS 1%

      scriptphp · picengineMay 16, 2008