phpkit kayıtları
phpkit üreticisine ait 20 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
20 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2016-10758İstismar yok | PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via thephpkit · phpkit · CWE-434 | Yüksek8,8 | — | %1,6 | 24 May 2019 |
31İzleyin | CVE-2005-2683Kavram kanıtı | Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameterphpkit · phpkit | Yüksek7,5 | — | %2,4 | 23 Ağu 2005 |
31İzleyin | CVE-2005-3553İstismar yok | Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL commandphpkit · phpkit · CWE-89 | Yüksek7,5 | — | %1,9 | 16 Kas 2005 |
30İzleyin | CVE-2006-7115İstismar yok | SQL injection vulnerability in PHPKit 1.6.1 RC2 allows remote attackers to inject arbitrary SQL commands via the catid parameter to include.phpkit · phpkit | Yüksek7,5 | — | %1,4 | 5 Mar 2007 |
30İzleyin | CVE-2004-1538İstismar yok | SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the phpkit · phpkit | Yüksek7,5 | — | %1,3 | 31 Ara 2004 |
30İzleyin | CVE-2007-6134Kavram kanıtı | SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via thephpkit · phpkit · CWE-89 | Yüksek7,5 | — | %1,1 | 27 Kas 2007 |
30İzleyin | CVE-2007-0179Kavram kanıtı | SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid paramephpkit · phpkit | Yüksek7,5 | — | %1,1 | 10 Oca 2007 |
28İzleyin | CVE-2003-1187Kavram kanıtı | Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script ophpkit · phpkit | Orta6,8 | — | %4,2 | 2 Kas 2003 |
27İzleyin | CVE-2005-4424İstismar yok | Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a phpkit · phpkit | Orta6,5 | — | %1,7 | 20 Ara 2005 |
27İzleyin | CVE-2006-1507İstismar yok | Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error paramphpkit · phpkit | Orta6,8 | — | %1,5 | 29 Mar 2006 |
27İzleyin | CVE-2008-7193İstismar yok | PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by rphpkit · phpkit · CWE-352 | Orta6,8 | — | %0,6 | 9 Eyl 2009 |
25İzleyin | CVE-2006-0785İstismar yok | Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arphpkit · phpkit | Orta6,4 | — | %1,6 | 19 Şub 2006 |
25İzleyin | CVE-2006-1773Kavram kanıtı | SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands vphpkit · phpkit | Orta6,4 | — | %1,1 | 13 Nis 2006 |
21İzleyin | CVE-2005-3554İstismar yok | Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote phpkit · phpkit · CWE-94 | Orta5,1 | — | %3,4 | 16 Kas 2005 |
21İzleyin | CVE-2006-0786Kavram kanıtı | Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackephpkit · phpkit | Orta5,1 | — | %2,4 | 19 Şub 2006 |
18İzleyin | CVE-2005-3552İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or phpkit · phpkit · CWE-79 | Orta4,3 | — | %2,0 | 16 Kas 2005 |
18İzleyin | CVE-2015-1052İstismar yok | Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT 1.6.6 (Build 160014) allows remote attackers to inject arbitrary web phpkit · phpkit · CWE-79 | Orta4,3 | — | %1,9 | 15 Oca 2015 |
18İzleyin | CVE-2004-1537Kavram kanıtı | Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web scriptphpkit · phpkit | Orta4,3 | — | %1,8 | 31 Ara 2004 |
18İzleyin | CVE-2005-2699İstismar yok | Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PHphpkit · phpkit | Orta4,6 | — | %0,5 | 26 Ağu 2005 |
17İzleyin | CVE-2004-1879İstismar yok | Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum mephpkit · phpkit | Orta4,3 | — | %1,2 | 31 Ara 2004 |
- CVE-2016-1075835İzleyin
PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the
YüksekCVSS 8,8İstismar yokEPSS %2phpkit · phpkit24 May 2019
- CVE-2005-268331İzleyin
Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter
YüksekCVSS 7,5Kavram kanıtıEPSS %2phpkit · phpkit23 Ağu 2005
- CVE-2005-355331İzleyin
Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL command
YüksekCVSS 7,5İstismar yokEPSS %2phpkit · phpkit16 Kas 2005
- CVE-2006-711530İzleyin
SQL injection vulnerability in PHPKit 1.6.1 RC2 allows remote attackers to inject arbitrary SQL commands via the catid parameter to include.
YüksekCVSS 7,5İstismar yokEPSS %1phpkit · phpkit5 Mar 2007
- CVE-2004-153830İzleyin
SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the
YüksekCVSS 7,5İstismar yokEPSS %1phpkit · phpkit31 Ara 2004
- CVE-2007-613430İzleyin
SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via the
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpkit · phpkit27 Kas 2007
- CVE-2007-017930İzleyin
SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parame
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpkit · phpkit10 Oca 2007
- CVE-2003-118728İzleyin
Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script o
OrtaCVSS 6,8Kavram kanıtıEPSS %4phpkit · phpkit2 Kas 2003
- CVE-2005-442427İzleyin
Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a
OrtaCVSS 6,5İstismar yokEPSS %2phpkit · phpkit20 Ara 2005
- CVE-2006-150727İzleyin
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error param
OrtaCVSS 6,8İstismar yokEPSS %1phpkit · phpkit29 Mar 2006
- CVE-2008-719327İzleyin
PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by r
OrtaCVSS 6,8İstismar yokEPSS %1phpkit · phpkit9 Eyl 2009
- CVE-2006-078525İzleyin
Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute ar
OrtaCVSS 6,4İstismar yokEPSS %2phpkit · phpkit19 Şub 2006
- CVE-2006-177325İzleyin
SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands v
OrtaCVSS 6,4Kavram kanıtıEPSS %1phpkit · phpkit13 Nis 2006
- CVE-2005-355421İzleyin
Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote
OrtaCVSS 5,1İstismar yokEPSS %3phpkit · phpkit16 Kas 2005
- CVE-2006-078621İzleyin
Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attacke
OrtaCVSS 5,1Kavram kanıtıEPSS %2phpkit · phpkit19 Şub 2006
- CVE-2005-355218İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or
OrtaCVSS 4,3İstismar yokEPSS %2phpkit · phpkit16 Kas 2005
- CVE-2015-105218İzleyin
Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT 1.6.6 (Build 160014) allows remote attackers to inject arbitrary web
OrtaCVSS 4,3İstismar yokEPSS %2phpkit · phpkit15 Oca 2015
- CVE-2004-153718İzleyin
Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script
OrtaCVSS 4,3Kavram kanıtıEPSS %2phpkit · phpkit31 Ara 2004
- CVE-2005-269918İzleyin
Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PH
OrtaCVSS 4,6İstismar yokEPSS %0phpkit · phpkit26 Ağu 2005
- CVE-2004-187917İzleyin
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum me
OrtaCVSS 4,3İstismar yokEPSS %1phpkit · phpkit31 Ara 2004