Перейти к содержимому
Noroxi

Записи phpgedview

17 опубликованных записей вендора phpgedview.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
6
С записью об исправлении
11,8 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Все записи

    17 записей
    • CVE-2004-0030
      41В плане

      PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 al

      КритическаяCVSS 9,8Proof of conceptEPSS 7 %

      phpgedview · phpgedview20 янв. 2004 г.

    • CVE-2008-2064
      41В плане

      Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw

      КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

      phpgedview · phpgedview2 мая 2008 г.

    • CVE-2004-0128
      32Наблюдать

      PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to exec

      ВысокаяCVSS 7,5Proof of conceptEPSS 8 %

      phpgedview · phpgedview3 мар. 2004 г.

    • CVE-2005-4468
      32Наблюдать

      PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary cod

      ВысокаяCVSS 7,5Proof of conceptEPSS 8 %

      phpgedview · phpgedview21 дек. 2005 г.

    • CVE-2005-4469
      31Наблюдать

      Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code v

      ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

      phpgedview · phpgedview21 дек. 2005 г.

    • CVE-2004-0127
      31Наблюдать

      Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      phpgedview · phpgedview3 мар. 2004 г.

    • CVE-2004-0065
      31Наблюдать

      Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      phpgedview · phpgedview17 февр. 2004 г.

    • CVE-2004-0031
      30Наблюдать

      PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editcon

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      phpgedview · phpgedview20 янв. 2004 г.

    • CVE-2011-0405
      29Наблюдать

      Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows r

      СредняяCVSS 6,8Proof of conceptEPSS 6 %

      phpgedview · phpgedview10 янв. 2011 г.

    • CVE-2004-0032
      28Наблюдать

      Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script vi

      СредняяCVSS 6,8Proof of conceptEPSS 2 %

      phpgedview · phpgedview20 янв. 2004 г.

    • CVE-2005-4467
      21Наблюдать

      Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrar

      СредняяCVSS 5,0Proof of conceptEPSS 5 %

      phpgedview · phpgedview21 дек. 2005 г.

    • CVE-2004-0033
      21Наблюдать

      admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.

      СредняяCVSS 5,0Proof of conceptEPSS 3 %

      phpgedview · phpgedview20 янв. 2004 г.

    • CVE-2004-0130
      20Наблюдать

      login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does

      СредняяCVSS 5,0Эксплойта нетEPSS 2 %

      phpgedview · phpgedview3 мар. 2004 г.

    • CVE-2004-0066
      20Наблюдать

      phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (

      СредняяCVSS 5,0Эксплойта нетEPSS 1 %

      phpgedview · phpgedview17 февр. 2004 г.

    • CVE-2011-3778
      20Наблюдать

      PhpGedView 4.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation

      СредняяCVSS 5,0Эксплойта нетEPSS 1 %

      phpgedview · phpgedview23 сент. 2011 г.

    • CVE-2004-0067
      18Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script

      СредняяCVSS 4,3Proof of conceptEPSS 3 %

      phpgedview · phpgedview17 февр. 2004 г.

    • CVE-2007-5051
      17Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in PhpGedView 4.1.1 allow remote attackers to inject arbitrary web script or HTML via th

      СредняяCVSS 4,3Эксплойта нетEPSS 1 %

      phpgedview · phpgedview23 сент. 2007 г.