Записи phpcms
18 опубликованных записей вендора phpcms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-400 Uncontrolled Resource Consumption1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2018-19127Proof of concept | A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controphpcms · phpcms · CWE-94 | Критическая9,8 | — | 20,8 % | 9 нояб. 2018 г. |
39Наблюдать | CVE-2020-22199Эксплойта нет | SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.phpcms · phpcms · CWE-89 | Критическая9,8 | — | 1,2 % | 16 июн. 2021 г. |
39Наблюдать | CVE-2020-22203Эксплойта нет | SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.phpcms · phpcms · CWE-89 | Критическая9,8 | — | 1,1 % | 16 июн. 2021 г. |
35Наблюдать | CVE-2020-22201Эксплойта нет | phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.phpcms · phpcms · CWE-94 | Высокая8,8 | — | 1,5 % | 16 июн. 2021 г. |
32Наблюдать | CVE-2006-3019Proof of concept | Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the phpcms · phpcms · CWE-94 | Высокая7,5 | — | 7,9 % | 15 июн. 2006 г. |
32Наблюдать | CVE-2008-0513Proof of concept | Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to read arbitrary files vphpcms · phpcms · CWE-22 | Высокая7,8 | — | 3,5 % | 31 янв. 2008 г. |
30Наблюдать | CVE-2018-14940Эксплойта нет | PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and width parameters in anphpcms · phpcms · CWE-400 | Высокая7,5 | — | 1,3 % | 5 авг. 2018 г. |
30Наблюдать | CVE-2011-0644Proof of concept | SQL injection vulnerability in include/admin/model_field.class.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commanphpcms · phpcms 2008 · CWE-89 | Высокая7,5 | — | 1,2 % | 25 янв. 2011 г. |
30Наблюдать | CVE-2011-0645Proof of concept | SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the where_time paramphpcms · phpcms 2008 · CWE-89 | Высокая7,5 | — | 1,0 % | 25 янв. 2011 г. |
28Наблюдать | CVE-2004-1202Эксплойта нет | Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote phpcms · phpcms | Средняя6,8 | — | 2,3 % | 10 янв. 2005 г. |
24Наблюдать | CVE-2021-40910Эксплойта нет | There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.phpcms · phpcms · CWE-79 | Средняя6,1 | — | 0,7 % | 15 июн. 2022 г. |
24Наблюдать | CVE-2025-25960Эксплойта нет | Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member phpcms · phpcms · CWE-79 | Средняя6,1 | — | 0,3 % | 20 февр. 2025 г. |
21Наблюдать | CVE-2005-1840Эксплойта нет | Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbiphpcms · phpcms | Средняя5,0 | — | 1,8 % | 2 июн. 2005 г. |
21Наблюдать | CVE-2020-22200Эксплойта нет | Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.phpcms · phpcms · CWE-22 | Средняя5,3 | — | 1,4 % | 16 июн. 2021 г. |
21Наблюдать | CVE-2025-25958Эксплойта нет | Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.phpcms · phpcms · CWE-79 | Средняя5,4 | — | 0,3 % | 20 февр. 2025 г. |
20Наблюдать | CVE-2004-1203Эксплойта нет | parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via phpcms · phpcms | Средняя5,0 | — | 1,4 % | 10 янв. 2005 г. |
19Наблюдать | CVE-2019-10027Эксплойта нет | PHPCMS 9.6.x through 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.phpcms · phpcms · CWE-79 | Средняя4,8 | — | 0,7 % | 24 мар. 2019 г. |
18Наблюдать | CVE-2013-5939Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the Guestbook module for PHPCMS allow remote attackers to inject arbitrary web scriptphpcms · guesbook module · CWE-79 | Средняя4,3 | — | 1,9 % | 14 мая 2014 г. |
- CVE-2018-1912745В плане
A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a contro
КритическаяCVSS 9,8Proof of conceptEPSS 21 %phpcms · phpcms9 нояб. 2018 г.
- CVE-2020-2219939Наблюдать
SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpcms · phpcms16 июн. 2021 г.
- CVE-2020-2220339Наблюдать
SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpcms · phpcms16 июн. 2021 г.
- CVE-2020-2220135Наблюдать
phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %phpcms · phpcms16 июн. 2021 г.
- CVE-2006-301932Наблюдать
Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %phpcms · phpcms15 июн. 2006 г.
- CVE-2008-051332Наблюдать
Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to read arbitrary files v
ВысокаяCVSS 7,8Proof of conceptEPSS 4 %phpcms · phpcms31 янв. 2008 г.
- CVE-2018-1494030Наблюдать
PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and width parameters in an
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %phpcms · phpcms5 авг. 2018 г.
- CVE-2011-064430Наблюдать
SQL injection vulnerability in include/admin/model_field.class.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL comman
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpcms · phpcms 200825 янв. 2011 г.
- CVE-2011-064530Наблюдать
SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via the where_time param
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpcms · phpcms 200825 янв. 2011 г.
- CVE-2004-120228Наблюдать
Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote
СредняяCVSS 6,8Эксплойта нетEPSS 2 %phpcms · phpcms10 янв. 2005 г.
- CVE-2021-4091024Наблюдать
There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %phpcms · phpcms15 июн. 2022 г.
- CVE-2025-2596024Наблюдать
Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member
СредняяCVSS 6,1Эксплойта нетEPSS 0 %phpcms · phpcms20 февр. 2025 г.
- CVE-2005-184021Наблюдать
Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbi
СредняяCVSS 5,0Эксплойта нетEPSS 2 %phpcms · phpcms2 июн. 2005 г.
- CVE-2020-2220021Наблюдать
Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %phpcms · phpcms16 июн. 2021 г.
- CVE-2025-2595821Наблюдать
Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %phpcms · phpcms20 февр. 2025 г.
- CVE-2004-120320Наблюдать
parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via
СредняяCVSS 5,0Эксплойта нетEPSS 1 %phpcms · phpcms10 янв. 2005 г.
- CVE-2019-1002719Наблюдать
PHPCMS 9.6.x through 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %phpcms · phpcms24 мар. 2019 г.
- CVE-2013-593918Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the Guestbook module for PHPCMS allow remote attackers to inject arbitrary web script
СредняяCVSS 4,3Эксплойта нетEPSS 2 %phpcms · guesbook module14 мая 2014 г.