Skip to content
Noroxi

thephpfactory records

11 published records for vendor thephpfactory.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 19

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

All records

11 records
  • SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    thephpfactory · swap factorySep 27, 2018

  • SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    thephpfactory · penny auction factorySep 27, 2018

  • SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    thephpfactory · raffle factorySep 27, 2018

  • SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    thephpfactory · article factory managerSep 27, 2018

  • SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    thephpfactory · collection factorySep 27, 2018

  • SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    thephpfactory · social factorySep 27, 2018

  • SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    thephpfactory · reverse auction factorySep 27, 2018

  • SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    thephpfactory · jobs factorySep 27, 2018

  • SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.

    CriticalCVSS 9.8No exploitEPSS 2%

    thephpfactory · auction factoryJun 19, 2019

  • SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.

    CriticalCVSS 9.8No exploitEPSS 2%

    thephpfactory · dutch auction factoryJun 19, 2019

  • SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.

    CriticalCVSS 9.8No exploitEPSS 2%

    thephpfactory · micro deal factoryJun 19, 2019