thephpfactory records
11 published records for vendor thephpfactory.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-17384Proof of concept | SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.thephpfactory · swap factory · CWE-89 | Critical9.8 | — | 3.3% | Sep 27, 2018 |
40Plan | CVE-2018-17378Proof of concept | SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.thephpfactory · penny auction factory · CWE-89 | Critical9.8 | — | 3.3% | Sep 27, 2018 |
40Plan | CVE-2018-17379Proof of concept | SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.thephpfactory · raffle factory · CWE-89 | Critical9.8 | — | 3.3% | Sep 27, 2018 |
40Plan | CVE-2018-17380Proof of concept | SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.thephpfactory · article factory manager · CWE-89 | Critical9.8 | — | 3.3% | Sep 27, 2018 |
40Plan | CVE-2018-17383Proof of concept | SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.thephpfactory · collection factory · CWE-89 | Critical9.8 | — | 3.2% | Sep 27, 2018 |
40Plan | CVE-2018-17385Proof of concept | SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.thephpfactory · social factory · CWE-89 | Critical9.8 | — | 3.2% | Sep 27, 2018 |
40Plan | CVE-2018-17376Proof of concept | SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.thephpfactory · reverse auction factory · CWE-89 | Critical9.8 | — | 3.2% | Sep 27, 2018 |
40Plan | CVE-2018-17382Proof of concept | SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.thephpfactory · jobs factory · CWE-89 | Critical9.8 | — | 3.2% | Sep 27, 2018 |
40Plan | CVE-2018-17374No exploit | SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.thephpfactory · auction factory · CWE-89 | Critical9.8 | — | 2.3% | Jun 19, 2019 |
40Plan | CVE-2018-17381No exploit | SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.thephpfactory · dutch auction factory · CWE-89 | Critical9.8 | — | 2.3% | Jun 19, 2019 |
40Plan | CVE-2018-17386No exploit | SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.thephpfactory · micro deal factory · CWE-89 | Critical9.8 | — | 2.3% | Jun 19, 2019 |
- CVE-2018-1738440Plan
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
CriticalCVSS 9.8Proof of conceptEPSS 3%thephpfactory · swap factorySep 27, 2018
- CVE-2018-1737840Plan
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.
CriticalCVSS 9.8Proof of conceptEPSS 3%thephpfactory · penny auction factorySep 27, 2018
- CVE-2018-1737940Plan
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
CriticalCVSS 9.8Proof of conceptEPSS 3%thephpfactory · raffle factorySep 27, 2018
- CVE-2018-1738040Plan
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.
CriticalCVSS 9.8Proof of conceptEPSS 3%thephpfactory · article factory managerSep 27, 2018
- CVE-2018-1738340Plan
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.
CriticalCVSS 9.8Proof of conceptEPSS 3%thephpfactory · collection factorySep 27, 2018
- CVE-2018-1738540Plan
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.
CriticalCVSS 9.8Proof of conceptEPSS 3%thephpfactory · social factorySep 27, 2018
- CVE-2018-1737640Plan
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
CriticalCVSS 9.8Proof of conceptEPSS 3%thephpfactory · reverse auction factorySep 27, 2018
- CVE-2018-1738240Plan
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
CriticalCVSS 9.8Proof of conceptEPSS 3%thephpfactory · jobs factorySep 27, 2018
- CVE-2018-1737440Plan
SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.
CriticalCVSS 9.8No exploitEPSS 2%thephpfactory · auction factoryJun 19, 2019
- CVE-2018-1738140Plan
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
CriticalCVSS 9.8No exploitEPSS 2%thephpfactory · dutch auction factoryJun 19, 2019
- CVE-2018-1738640Plan
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.
CriticalCVSS 9.8No exploitEPSS 2%thephpfactory · micro deal factoryJun 19, 2019