Записи php arena
32 опубликованных записей вендора php arena.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 14
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
32 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2006-2361Proof of concept | PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allowmxbb · mxbb portal | Высокая7,5 | — | 3,2 % | 15 мая 2006 г. |
31Наблюдать | CVE-2006-5079Proof of concept | PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to executephp arena · pabugs | Высокая7,5 | — | 2,7 % | 28 сент. 2006 г. |
31Наблюдать | CVE-2007-3808Proof of concept | SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categorphp arena · pafiledb | Высокая7,5 | — | 2,5 % | 16 июл. 2007 г. |
31Наблюдать | CVE-2005-2000Proof of concept | Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formnamephp arena · pafiledb | Высокая7,5 | — | 2,4 % | 15 июн. 2005 г. |
31Наблюдать | CVE-2005-0781Proof of concept | SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitraryphp arena · pafiledb | Высокая7,5 | — | 2,4 % | 2 мая 2005 г. |
31Наблюдать | CVE-2005-0327Эксплойта нет | pafiledb.php in Pafiledb 3.1 may allow remote attackers to execute arbitrary PHP code via a modified action parameter that is used in an incphp arena · pafiledb | Высокая7,5 | — | 1,9 % | 2 мая 2005 г. |
30Наблюдать | CVE-2005-2723Эксплойта нет | SQL injection vulnerability in auth.php in PaFileDB 3.1, when authmethod is set to cookies, allows remote attackers to execute arbitrary SQLphp arena · pafiledb | Высокая7,5 | — | 1,3 % | 30 авг. 2005 г. |
30Наблюдать | CVE-2005-2012Proof of concept | Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authphp arena · pafaq | Высокая7,5 | — | 1,2 % | 20 июн. 2005 г. |
30Наблюдать | CVE-2005-4329Proof of concept | SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitrphp arena · pafiledb | Высокая7,5 | — | 1,2 % | 17 дек. 2005 г. |
30Наблюдать | CVE-2005-0646Эксплойта нет | SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql_prefix parameter.php arena · panews | Высокая7,5 | — | 1,1 % | 2 мая 2005 г. |
30Наблюдать | CVE-2007-4183Proof of concept | SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the cphp arena · pabugs | Высокая7,5 | — | 1,0 % | 7 авг. 2007 г. |
25Наблюдать | CVE-2006-2209Proof of concept | Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands viphp arena · pacheckbook | Средняя6,4 | — | 1,2 % | 5 мая 2006 г. |
25Наблюдать | CVE-2005-0475Proof of concept | SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) ophp arena · pafaq | Средняя6,4 | — | 1,0 % | 30 мар. 2005 г. |
22Наблюдать | CVE-2005-0952Proof of concept | Cross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the idphp arena · pafiledb | Средняя5,0 | — | 5,9 % | 2 мая 2005 г. |
22Наблюдать | CVE-2005-0780Proof of concept | paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) caphp arena · pafiledb | Средняя5,0 | — | 5,1 % | 12 мар. 2005 г. |
21Наблюдать | CVE-2005-0647Proof of concept | admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] php arena · panews | Средняя5,0 | — | 4,2 % | 2 мая 2005 г. |
21Наблюдать | CVE-2004-1219Эксплойта нет | paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's paphp arena · pafiledb | Средняя5,0 | — | 2,3 % | 10 янв. 2005 г. |
21Наблюдать | CVE-2005-2001Эксплойта нет | Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a ..php arena · pafiledb | Средняя5,0 | — | 1,8 % | 15 июн. 2005 г. |
20Наблюдать | CVE-2005-2013Эксплойта нет | paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, which contains a backup ophp arena · pafaq | Средняя5,0 | — | 1,3 % | 20 июн. 2005 г. |
20Наблюдать | CVE-2005-0724Эксплойта нет | paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via (1) an invalid str parameter to pafiledb.php, or a direphp arena · pafiledb | Средняя5,0 | — | 1,2 % | 2 мая 2005 г. |
20Наблюдать | CVE-2004-1974Эксплойта нет | paFileDB 3.1 allows remote attackers to gain sensitive information via a direct request to (1) login.php, (2) category.php, (3) search.php, php arena · pafiledb | Средняя5,0 | — | 1,2 % | 27 апр. 2004 г. |
20Наблюдать | CVE-2005-0326Эксплойта нет | pafiledb.php in PaFileDB 3.1 allows remote attackers to gain sensitive information via an invalid or missing action parameter, which revealsphp arena · pafiledb | Средняя5,0 | — | 1,2 % | 2 мая 2005 г. |
18Наблюдать | CVE-2005-0782Proof of concept | Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to injphp arena · pafiledb | Средняя4,3 | — | 3,6 % | 2 мая 2005 г. |
18Наблюдать | CVE-2004-1551Proof of concept | Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitphp arena · pafiledb | Средняя4,3 | — | 2,6 % | 31 дек. 2004 г. |
18Наблюдать | CVE-2002-1929Proof of concept | Cross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena paFileDB 1.1.3 through 3.0 allows remote attackers to inject arbitraryphp arena · pafiledb | Средняя4,3 | — | 1,9 % | 31 дек. 2002 г. |
- CVE-2006-236131Наблюдать
PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allow
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %mxbb · mxbb portal15 мая 2006 г.
- CVE-2006-507931Наблюдать
PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %php arena · pabugs28 сент. 2006 г.
- CVE-2007-380831Наблюдать
SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categor
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %php arena · pafiledb16 июл. 2007 г.
- CVE-2005-200031Наблюдать
Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %php arena · pafiledb15 июн. 2005 г.
- CVE-2005-078131Наблюдать
SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %php arena · pafiledb2 мая 2005 г.
- CVE-2005-032731Наблюдать
pafiledb.php in Pafiledb 3.1 may allow remote attackers to execute arbitrary PHP code via a modified action parameter that is used in an inc
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %php arena · pafiledb2 мая 2005 г.
- CVE-2005-272330Наблюдать
SQL injection vulnerability in auth.php in PaFileDB 3.1, when authmethod is set to cookies, allows remote attackers to execute arbitrary SQL
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %php arena · pafiledb30 авг. 2005 г.
- CVE-2005-201230Наблюдать
Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass auth
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php arena · pafaq20 июн. 2005 г.
- CVE-2005-432930Наблюдать
SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitr
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php arena · pafiledb17 дек. 2005 г.
- CVE-2005-064630Наблюдать
SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql_prefix parameter.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %php arena · panews2 мая 2005 г.
- CVE-2007-418330Наблюдать
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the c
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php arena · pabugs7 авг. 2007 г.
- CVE-2006-220925Наблюдать
Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands vi
СредняяCVSS 6,4Proof of conceptEPSS 1 %php arena · pacheckbook5 мая 2006 г.
- CVE-2005-047525Наблюдать
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) o
СредняяCVSS 6,4Proof of conceptEPSS 1 %php arena · pafaq30 мар. 2005 г.
- CVE-2005-095222Наблюдать
Cross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id
СредняяCVSS 5,0Proof of conceptEPSS 6 %php arena · pafiledb2 мая 2005 г.
- CVE-2005-078022Наблюдать
paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) ca
СредняяCVSS 5,0Proof of conceptEPSS 5 %php arena · pafiledb12 мар. 2005 г.
- CVE-2005-064721Наблюдать
admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove]
СредняяCVSS 5,0Proof of conceptEPSS 4 %php arena · panews2 мая 2005 г.
- CVE-2004-121921Наблюдать
paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's pa
СредняяCVSS 5,0Эксплойта нетEPSS 2 %php arena · pafiledb10 янв. 2005 г.
- CVE-2005-200121Наблюдать
Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a ..
СредняяCVSS 5,0Эксплойта нетEPSS 2 %php arena · pafiledb15 июн. 2005 г.
- CVE-2005-201320Наблюдать
paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, which contains a backup o
СредняяCVSS 5,0Эксплойта нетEPSS 1 %php arena · pafaq20 июн. 2005 г.
- CVE-2005-072420Наблюдать
paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via (1) an invalid str parameter to pafiledb.php, or a dire
СредняяCVSS 5,0Эксплойта нетEPSS 1 %php arena · pafiledb2 мая 2005 г.
- CVE-2004-197420Наблюдать
paFileDB 3.1 allows remote attackers to gain sensitive information via a direct request to (1) login.php, (2) category.php, (3) search.php,
СредняяCVSS 5,0Эксплойта нетEPSS 1 %php arena · pafiledb27 апр. 2004 г.
- CVE-2005-032620Наблюдать
pafiledb.php in PaFileDB 3.1 allows remote attackers to gain sensitive information via an invalid or missing action parameter, which reveals
СредняяCVSS 5,0Эксплойта нетEPSS 1 %php arena · pafiledb2 мая 2005 г.
- CVE-2005-078218Наблюдать
Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inj
СредняяCVSS 4,3Proof of conceptEPSS 4 %php arena · pafiledb2 мая 2005 г.
- CVE-2004-155118Наблюдать
Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbit
СредняяCVSS 4,3Proof of conceptEPSS 3 %php arena · pafiledb31 дек. 2004 г.
- CVE-2002-192918Наблюдать
Cross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena paFileDB 1.1.3 through 3.0 allows remote attackers to inject arbitrary
СредняяCVSS 4,3Proof of conceptEPSS 2 %php arena · pafiledb31 дек. 2002 г.