vwar records
22 published records for vendor vwar.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 12
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-255 Credentials Management Errors1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-189 Numeric Errors1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-1747Proof of concept | PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vvwar · virtual war | High7.5 | — | 4.0% | Apr 12, 2006 |
31Monitor | CVE-2007-4605Proof of concept | PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute avwar · virtual war · CWE-94 | High7.5 | — | 2.1% | Aug 30, 2007 |
31Monitor | CVE-2006-1636No exploit | PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute arbitrary PHP codvwar · virtual war · CWE-94 | High7.5 | — | 2.1% | Apr 6, 2006 |
31Monitor | CVE-2006-4010Proof of concept | SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands viavwar · virtual war · CWE-89 | High7.5 | — | 1.8% | Aug 7, 2006 |
31Monitor | CVE-2006-3139No exploit | Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQvwar · virtual war · CWE-89 | High7.5 | — | 1.8% | Jun 22, 2006 |
30Monitor | CVE-2006-4142Proof of concept | SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQLvwar · virtual war | High7.5 | — | 1.3% | Aug 14, 2006 |
30Monitor | CVE-2006-4141No exploit | SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands vivwar · virtual war | High7.5 | — | 1.2% | Aug 14, 2006 |
30Monitor | CVE-2007-2312Proof of concept | Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary Svwar · virtual war | High7.5 | — | 1.2% | Apr 26, 2007 |
30Monitor | CVE-2010-5063Proof of concept | SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via vwar · virtual war · CWE-89 | High7.5 | — | 1.1% | Oct 8, 2012 |
30Monitor | CVE-2008-0753Proof of concept | SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the montvwar · virtual war · CWE-89 | High7.5 | — | 1.0% | Feb 13, 2008 |
27Monitor | CVE-2010-5067No exploit | Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for remote attackervwar · virtual war · CWE-255 | Medium6.8 | — | 1.3% | Oct 8, 2012 |
27Monitor | CVE-2005-4748No exploit | PHP remote file include vulnerability in functions_admin.php in Virtual War (VWar) 1.5.0 R10 allows remote attackers to include and execute vwar · virtual war | Medium6.8 | — | 1.3% | Dec 31, 2005 |
21Monitor | CVE-2006-1503No exploit | PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attackervwar · virtual war · CWE-94 | Medium5.1 | — | 2.0% | Mar 29, 2006 |
20Monitor | CVE-2006-2091No exploit | admin.php in Virtual War (VWar) 1.5 and versions before 1.2 allows remote attackers to obtain sensitive information via an invalid vwar_rootvwar · virtual war | Medium5.0 | — | 1.4% | Apr 29, 2006 |
20Monitor | CVE-2010-5065No exploit | popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news posts via a modifivwar · virtual war · CWE-264 | Medium5.0 | — | 1.4% | Oct 8, 2012 |
20Monitor | CVE-2010-5279No exploit | article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to cause a denial of service (memory consumption) via a large integervwar · virtual war · CWE-189 | Medium5.0 | — | 1.3% | Oct 8, 2012 |
20Monitor | CVE-2011-3813No exploit | Virtual War (aka VWar) 1.5.0r15 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals tvwar · virtual war · CWE-200 | Medium5.0 | — | 1.2% | Sep 23, 2011 |
18Monitor | CVE-2006-4009Proof of concept | Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary web vwar · virtual war | Medium4.3 | — | 1.7% | Aug 7, 2006 |
17Monitor | CVE-2010-5066No exploit | The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to selectvwar · virtual war · CWE-310 | Medium4.3 | — | 1.2% | Oct 8, 2012 |
17Monitor | CVE-2006-4224No exploit | Cross-site scripting (XSS) vulnerability in calendar.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to inject arbitraryvwar · virtual war | Medium4.3 | — | 1.2% | Aug 18, 2006 |
17Monitor | CVE-2007-2306No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globavwar · virtual war | Medium4.3 | — | 1.1% | Apr 26, 2007 |
17Monitor | CVE-2010-5064No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Virtual War (aka VWar) 1.6.1 R2 allow remote attackers to inject arbitrary web scriptvwar · virtual war · CWE-79 | Medium4.3 | — | 1.0% | Oct 8, 2012 |
- CVE-2006-174731Monitor
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the v
HighCVSS 7.5Proof of conceptEPSS 4%vwar · virtual warApr 12, 2006
- CVE-2007-460531Monitor
PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute a
HighCVSS 7.5Proof of conceptEPSS 2%vwar · virtual warAug 30, 2007
- CVE-2006-163631Monitor
PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute arbitrary PHP cod
HighCVSS 7.5No exploitEPSS 2%vwar · virtual warApr 6, 2006
- CVE-2006-401031Monitor
SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 2%vwar · virtual warAug 7, 2006
- CVE-2006-313931Monitor
Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQ
HighCVSS 7.5No exploitEPSS 2%vwar · virtual warJun 22, 2006
- CVE-2006-414230Monitor
SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQL
HighCVSS 7.5Proof of conceptEPSS 1%vwar · virtual warAug 14, 2006
- CVE-2006-414130Monitor
SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands vi
HighCVSS 7.5No exploitEPSS 1%vwar · virtual warAug 14, 2006
- CVE-2007-231230Monitor
Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary S
HighCVSS 7.5Proof of conceptEPSS 1%vwar · virtual warApr 26, 2007
- CVE-2010-506330Monitor
SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%vwar · virtual warOct 8, 2012
- CVE-2008-075330Monitor
SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the mont
HighCVSS 7.5Proof of conceptEPSS 1%vwar · virtual warFeb 13, 2008
- CVE-2010-506727Monitor
Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for remote attacker
MediumCVSS 6.8No exploitEPSS 1%vwar · virtual warOct 8, 2012
- CVE-2005-474827Monitor
PHP remote file include vulnerability in functions_admin.php in Virtual War (VWar) 1.5.0 R10 allows remote attackers to include and execute
MediumCVSS 6.8No exploitEPSS 1%vwar · virtual warDec 31, 2005
- CVE-2006-150321Monitor
PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attacker
MediumCVSS 5.1No exploitEPSS 2%vwar · virtual warMar 29, 2006
- CVE-2006-209120Monitor
admin.php in Virtual War (VWar) 1.5 and versions before 1.2 allows remote attackers to obtain sensitive information via an invalid vwar_root
MediumCVSS 5.0No exploitEPSS 1%vwar · virtual warApr 29, 2006
- CVE-2010-506520Monitor
popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news posts via a modifi
MediumCVSS 5.0No exploitEPSS 1%vwar · virtual warOct 8, 2012
- CVE-2010-527920Monitor
article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to cause a denial of service (memory consumption) via a large integer
MediumCVSS 5.0No exploitEPSS 1%vwar · virtual warOct 8, 2012
- CVE-2011-381320Monitor
Virtual War (aka VWar) 1.5.0r15 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals t
MediumCVSS 5.0No exploitEPSS 1%vwar · virtual warSep 23, 2011
- CVE-2006-400918Monitor
Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary web
MediumCVSS 4.3Proof of conceptEPSS 2%vwar · virtual warAug 7, 2006
- CVE-2010-506617Monitor
The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to select
MediumCVSS 4.3No exploitEPSS 1%vwar · virtual warOct 8, 2012
- CVE-2006-422417Monitor
Cross-site scripting (XSS) vulnerability in calendar.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to inject arbitrary
MediumCVSS 4.3No exploitEPSS 1%vwar · virtual warAug 18, 2006
- CVE-2007-230617Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globa
MediumCVSS 4.3No exploitEPSS 1%vwar · virtual warApr 26, 2007
- CVE-2010-506417Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Virtual War (aka VWar) 1.6.1 R2 allow remote attackers to inject arbitrary web script
MediumCVSS 4.3No exploitEPSS 1%vwar · virtual warOct 8, 2012