Перейти к содержимому
Noroxi

Записи php arena

32 опубликованных записей вендора php arena.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
14
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Повторяющиеся классы

      Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

      CWE

      Все записи

      32 записей
      • CVE-2006-2361
        31Наблюдать

        PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allow

        ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

        mxbb · mxbb portal15 мая 2006 г.

      • CVE-2006-5079
        31Наблюдать

        PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute

        ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

        php arena · pabugs28 сент. 2006 г.

      • CVE-2007-3808
        31Наблюдать

        SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categor

        ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

        php arena · pafiledb16 июл. 2007 г.

      • CVE-2005-2000
        31Наблюдать

        Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname

        ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

        php arena · pafiledb15 июн. 2005 г.

      • CVE-2005-0781
        31Наблюдать

        SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary

        ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

        php arena · pafiledb2 мая 2005 г.

      • CVE-2005-0327
        31Наблюдать

        pafiledb.php in Pafiledb 3.1 may allow remote attackers to execute arbitrary PHP code via a modified action parameter that is used in an inc

        ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

        php arena · pafiledb2 мая 2005 г.

      • CVE-2005-2723
        30Наблюдать

        SQL injection vulnerability in auth.php in PaFileDB 3.1, when authmethod is set to cookies, allows remote attackers to execute arbitrary SQL

        ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

        php arena · pafiledb30 авг. 2005 г.

      • CVE-2005-2012
        30Наблюдать

        Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass auth

        ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

        php arena · pafaq20 июн. 2005 г.

      • CVE-2005-4329
        30Наблюдать

        SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitr

        ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

        php arena · pafiledb17 дек. 2005 г.

      • CVE-2005-0646
        30Наблюдать

        SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql_prefix parameter.

        ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

        php arena · panews2 мая 2005 г.

      • CVE-2007-4183
        30Наблюдать

        SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the c

        ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

        php arena · pabugs7 авг. 2007 г.

      • CVE-2006-2209
        25Наблюдать

        Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands vi

        СредняяCVSS 6,4Proof of conceptEPSS 1 %

        php arena · pacheckbook5 мая 2006 г.

      • CVE-2005-0475
        25Наблюдать

        SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) o

        СредняяCVSS 6,4Proof of conceptEPSS 1 %

        php arena · pafaq30 мар. 2005 г.

      • CVE-2005-0952
        22Наблюдать

        Cross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id

        СредняяCVSS 5,0Proof of conceptEPSS 6 %

        php arena · pafiledb2 мая 2005 г.

      • CVE-2005-0780
        22Наблюдать

        paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) ca

        СредняяCVSS 5,0Proof of conceptEPSS 5 %

        php arena · pafiledb12 мар. 2005 г.

      • CVE-2005-0647
        21Наблюдать

        admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove]

        СредняяCVSS 5,0Proof of conceptEPSS 4 %

        php arena · panews2 мая 2005 г.

      • CVE-2004-1219
        21Наблюдать

        paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's pa

        СредняяCVSS 5,0Эксплойта нетEPSS 2 %

        php arena · pafiledb10 янв. 2005 г.

      • CVE-2005-2001
        21Наблюдать

        Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a ..

        СредняяCVSS 5,0Эксплойта нетEPSS 2 %

        php arena · pafiledb15 июн. 2005 г.

      • CVE-2005-2013
        20Наблюдать

        paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, which contains a backup o

        СредняяCVSS 5,0Эксплойта нетEPSS 1 %

        php arena · pafaq20 июн. 2005 г.

      • CVE-2005-0724
        20Наблюдать

        paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via (1) an invalid str parameter to pafiledb.php, or a dire

        СредняяCVSS 5,0Эксплойта нетEPSS 1 %

        php arena · pafiledb2 мая 2005 г.

      • CVE-2004-1974
        20Наблюдать

        paFileDB 3.1 allows remote attackers to gain sensitive information via a direct request to (1) login.php, (2) category.php, (3) search.php,

        СредняяCVSS 5,0Эксплойта нетEPSS 1 %

        php arena · pafiledb27 апр. 2004 г.

      • CVE-2005-0326
        20Наблюдать

        pafiledb.php in PaFileDB 3.1 allows remote attackers to gain sensitive information via an invalid or missing action parameter, which reveals

        СредняяCVSS 5,0Эксплойта нетEPSS 1 %

        php arena · pafiledb2 мая 2005 г.

      • CVE-2005-0782
        18Наблюдать

        Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inj

        СредняяCVSS 4,3Proof of conceptEPSS 4 %

        php arena · pafiledb2 мая 2005 г.

      • CVE-2004-1551
        18Наблюдать

        Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbit

        СредняяCVSS 4,3Proof of conceptEPSS 3 %

        php arena · pafiledb31 дек. 2004 г.

      • CVE-2002-1929
        18Наблюдать

        Cross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena paFileDB 1.1.3 through 3.0 allows remote attackers to inject arbitrary

        СредняяCVSS 4,3Proof of conceptEPSS 2 %

        php arena · pafiledb31 дек. 2002 г.