Перейти к содержимому
Noroxi

Записи phpx

12 опубликованных записей вендора phpx.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
7
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Повторяющиеся классы

    Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

    CWE

    Все записи

    12 записей
    • CVE-2004-0249
      41В плане

      PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another

      КритическаяCVSS 10,0Proof of conceptEPSS 5 %

      phpx · phpx23 нояб. 2004 г.

    • CVE-2007-1550
      31Наблюдать

      Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) c

      ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

      phpx · phpx20 мар. 2007 г.

    • CVE-2005-3968
      31Наблюдать

      SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass auth

      ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

      phpx · phpx3 дек. 2005 г.

    • CVE-2008-3489
      30Наблюдать

      SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers to execute arbitrar

      ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

      phpx · phpx6 авг. 2008 г.

    • CVE-2004-0248
      27Наблюдать

      Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbit

      СредняяCVSS 6,8Эксплойта нетEPSS 1 %

      phpx · phpx23 нояб. 2004 г.

    • CVE-2007-1549
      27Наблюдать

      Unrestricted file upload vulnerability in gallery.php in phpx 3.5.15 allows remote attackers to upload and execute arbitrary PHP scripts via

      СредняяCVSS 6,8Эксплойта нетEPSS 1 %

      phpx · phpx20 мар. 2007 г.

    • CVE-2008-5000
      27Наблюдать

      SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows remote attackers to exe

      СредняяCVSS 6,8Proof of conceptEPSS 1 %

      phpx · phpx10 нояб. 2008 г.

    • CVE-2004-2364
      23Наблюдать

      Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs tha

      СредняяCVSS 5,0Proof of conceptEPSS 11 %

      phpx · phpx31 дек. 2004 г.

    • CVE-2004-2362
      21Наблюдать

      PHPX 3.2.6 and earlier allows remote attackers to obtain the physical path of PHPX via a null or invalid value in the limit parameter, which

      СредняяCVSS 5,0Эксплойта нетEPSS 2 %

      phpx · phpx31 дек. 2004 г.

    • CVE-2004-2363
      18Наблюдать

      Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers t

      СредняяCVSS 4,3Proof of conceptEPSS 2 %

      phpx · phpx31 дек. 2004 г.

    • CVE-2006-0933
      18Наблюдать

      Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI i

      СредняяCVSS 4,3Proof of conceptEPSS 2 %

      phpx · phpx28 февр. 2006 г.

    • CVE-2007-1551
      17Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in phpx 3.5.15 allow remote attackers to inject arbitrary web script or HTML via (1) the

      СредняяCVSS 4,3Эксплойта нетEPSS 2 %

      phpx · phpx20 мар. 2007 г.