Записи phpkit
20 опубликованных записей вендора phpkit.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
20 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2016-10758Эксплойта нет | PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via thephpkit · phpkit · CWE-434 | Высокая8,8 | — | 1,6 % | 24 мая 2019 г. |
31Наблюдать | CVE-2005-2683Proof of concept | Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameterphpkit · phpkit | Высокая7,5 | — | 2,4 % | 23 авг. 2005 г. |
31Наблюдать | CVE-2005-3553Эксплойта нет | Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL commandphpkit · phpkit · CWE-89 | Высокая7,5 | — | 1,9 % | 16 нояб. 2005 г. |
30Наблюдать | CVE-2006-7115Эксплойта нет | SQL injection vulnerability in PHPKit 1.6.1 RC2 allows remote attackers to inject arbitrary SQL commands via the catid parameter to include.phpkit · phpkit | Высокая7,5 | — | 1,4 % | 5 мар. 2007 г. |
30Наблюдать | CVE-2004-1538Эксплойта нет | SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the phpkit · phpkit | Высокая7,5 | — | 1,3 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2007-6134Proof of concept | SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via thephpkit · phpkit · CWE-89 | Высокая7,5 | — | 1,1 % | 27 нояб. 2007 г. |
30Наблюдать | CVE-2007-0179Proof of concept | SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid paramephpkit · phpkit | Высокая7,5 | — | 1,1 % | 10 янв. 2007 г. |
28Наблюдать | CVE-2003-1187Proof of concept | Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script ophpkit · phpkit | Средняя6,8 | — | 4,2 % | 2 нояб. 2003 г. |
27Наблюдать | CVE-2005-4424Эксплойта нет | Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a phpkit · phpkit | Средняя6,5 | — | 1,7 % | 20 дек. 2005 г. |
27Наблюдать | CVE-2006-1507Эксплойта нет | Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error paramphpkit · phpkit | Средняя6,8 | — | 1,5 % | 29 мар. 2006 г. |
27Наблюдать | CVE-2008-7193Эксплойта нет | PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by rphpkit · phpkit · CWE-352 | Средняя6,8 | — | 0,6 % | 9 сент. 2009 г. |
25Наблюдать | CVE-2006-0785Эксплойта нет | Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arphpkit · phpkit | Средняя6,4 | — | 1,6 % | 19 февр. 2006 г. |
25Наблюдать | CVE-2006-1773Proof of concept | SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands vphpkit · phpkit | Средняя6,4 | — | 1,1 % | 13 апр. 2006 г. |
21Наблюдать | CVE-2005-3554Эксплойта нет | Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote phpkit · phpkit · CWE-94 | Средняя5,1 | — | 3,4 % | 16 нояб. 2005 г. |
21Наблюдать | CVE-2006-0786Proof of concept | Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackephpkit · phpkit | Средняя5,1 | — | 2,4 % | 19 февр. 2006 г. |
18Наблюдать | CVE-2005-3552Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or phpkit · phpkit · CWE-79 | Средняя4,3 | — | 2,0 % | 16 нояб. 2005 г. |
18Наблюдать | CVE-2015-1052Эксплойта нет | Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT 1.6.6 (Build 160014) allows remote attackers to inject arbitrary web phpkit · phpkit · CWE-79 | Средняя4,3 | — | 1,9 % | 15 янв. 2015 г. |
18Наблюдать | CVE-2004-1537Proof of concept | Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web scriptphpkit · phpkit | Средняя4,3 | — | 1,8 % | 31 дек. 2004 г. |
18Наблюдать | CVE-2005-2699Эксплойта нет | Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PHphpkit · phpkit | Средняя4,6 | — | 0,5 % | 26 авг. 2005 г. |
17Наблюдать | CVE-2004-1879Эксплойта нет | Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum mephpkit · phpkit | Средняя4,3 | — | 1,2 % | 31 дек. 2004 г. |
- CVE-2016-1075835Наблюдать
PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %phpkit · phpkit24 мая 2019 г.
- CVE-2005-268331Наблюдать
Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %phpkit · phpkit23 авг. 2005 г.
- CVE-2005-355331Наблюдать
Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL command
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %phpkit · phpkit16 нояб. 2005 г.
- CVE-2006-711530Наблюдать
SQL injection vulnerability in PHPKit 1.6.1 RC2 allows remote attackers to inject arbitrary SQL commands via the catid parameter to include.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %phpkit · phpkit5 мар. 2007 г.
- CVE-2004-153830Наблюдать
SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %phpkit · phpkit31 дек. 2004 г.
- CVE-2007-613430Наблюдать
SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via the
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpkit · phpkit27 нояб. 2007 г.
- CVE-2007-017930Наблюдать
SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parame
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpkit · phpkit10 янв. 2007 г.
- CVE-2003-118728Наблюдать
Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script o
СредняяCVSS 6,8Proof of conceptEPSS 4 %phpkit · phpkit2 нояб. 2003 г.
- CVE-2005-442427Наблюдать
Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a
СредняяCVSS 6,5Эксплойта нетEPSS 2 %phpkit · phpkit20 дек. 2005 г.
- CVE-2006-150727Наблюдать
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error param
СредняяCVSS 6,8Эксплойта нетEPSS 1 %phpkit · phpkit29 мар. 2006 г.
- CVE-2008-719327Наблюдать
PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by r
СредняяCVSS 6,8Эксплойта нетEPSS 1 %phpkit · phpkit9 сент. 2009 г.
- CVE-2006-078525Наблюдать
Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute ar
СредняяCVSS 6,4Эксплойта нетEPSS 2 %phpkit · phpkit19 февр. 2006 г.
- CVE-2006-177325Наблюдать
SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands v
СредняяCVSS 6,4Proof of conceptEPSS 1 %phpkit · phpkit13 апр. 2006 г.
- CVE-2005-355421Наблюдать
Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote
СредняяCVSS 5,1Эксплойта нетEPSS 3 %phpkit · phpkit16 нояб. 2005 г.
- CVE-2006-078621Наблюдать
Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attacke
СредняяCVSS 5,1Proof of conceptEPSS 2 %phpkit · phpkit19 февр. 2006 г.
- CVE-2005-355218Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or
СредняяCVSS 4,3Эксплойта нетEPSS 2 %phpkit · phpkit16 нояб. 2005 г.
- CVE-2015-105218Наблюдать
Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT 1.6.6 (Build 160014) allows remote attackers to inject arbitrary web
СредняяCVSS 4,3Эксплойта нетEPSS 2 %phpkit · phpkit15 янв. 2015 г.
- CVE-2004-153718Наблюдать
Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script
СредняяCVSS 4,3Proof of conceptEPSS 2 %phpkit · phpkit31 дек. 2004 г.
- CVE-2005-269918Наблюдать
Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PH
СредняяCVSS 4,6Эксплойта нетEPSS 0 %phpkit · phpkit26 авг. 2005 г.
- CVE-2004-187917Наблюдать
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum me
СредняяCVSS 4,3Эксплойта нетEPSS 1 %phpkit · phpkit31 дек. 2004 г.