İçeriğe atla
Noroxi

phpfox kayıtları

phpfox üreticisine ait 10 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
5
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

10 kayıt
  • CVE-2023-46817
    40Planlayın

    An issue was discovered in phpFox before 4.8.14.

    KritikCVSS 9,8İstismar yokEPSS %2

    phpfox · phpfox3 Kas 2023

  • CVE-2013-5120
    30İzleyin

    SQL injection vulnerability in PHPFox before 3.6.0 (build4) allows remote attackers to execute arbitrary SQL commands via the search[gender]

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    phpfox · phpfox14 Ağu 2013

  • CVE-2013-5121
    30İzleyin

    SQL injection vulnerability in PHPFox before 3.6.0 (build6) allows remote attackers to execute arbitrary SQL commands via the search[sort_by

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    phpfox · phpfox14 Ağu 2013

  • CVE-2022-34560
    28İzleyin

    A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload

    YüksekCVSS 7,1İstismar yokEPSS %0

    phpfox · phpfox22 Nis 2024

  • CVE-2009-0969
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in account/settings/account/index.php in phpFoX 1.6.21 allows remote attackers to hijack the

    OrtaCVSS 6,8İstismar yokEPSS %1

    phpfox · phpfox19 Mar 2009

  • CVE-2022-34562
    24İzleyin

    A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload

    OrtaCVSS 6,1İstismar yokEPSS %0

    phpfox · phpfox22 Nis 2024

  • CVE-2013-7196
    23İzleyin

    static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on

    OrtaCVSS 5,5Kavram kanıtıEPSS %2

    phpfox · phpfox18 Nis 2014

  • CVE-2013-7195
    22İzleyin

    PHPFox 3.7.3 and 3.7.4 allows remote authenticated users to bypass intended "Only Me" restrictions and "like" a publication via a request th

    OrtaCVSS 5,5İstismar yokEPSS %1

    phpfox · phpfox18 Nis 2014

  • CVE-2022-34561
    17İzleyin

    A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload

    OrtaCVSS 4,3İstismar yokEPSS %0

    phpfox · phpfox22 Nis 2024

  • CVE-2006-2631
    16İzleyin

    phpFoX allows remote authenticated users to modify arbitrary accounts via a modified NATIO cookie value, possibly the phpfox_user parameter.

    OrtaCVSS 4,0İstismar yokEPSS %1

    phpfox · phpfox27 May 2006