phprojekt kayıtları
phprojekt üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
32İzleyin | CVE-2006-4204Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execute arbitrary PHP codphprojekt · phprojekt · CWE-94 | Yüksek7,5 | — | %8,1 | 17 Ağu 2006 |
31İzleyin | CVE-2002-1757Kavram kanıtı | PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scphprojekt · phprojekt | Yüksek7,5 | — | %3,1 | 31 Ara 2002 |
31İzleyin | CVE-2006-5123İstismar yok | Multiple PHP remote file inclusion vulnerabilities in Albrecht Guenther PHProjekt 5.1.x before 5.1.2 allow remote attackers to execute arbitphprojekt · phprojekt | Yüksek7,5 | — | %2,2 | 3 Eki 2006 |
31İzleyin | CVE-2007-1575İstismar yok | Multiple SQL injection vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arphprojekt · phprojekt | Yüksek7,5 | — | %2,0 | 21 Mar 2007 |
31İzleyin | CVE-2004-2739İstismar yok | The setup routine (setup.php) in PHProjekt 4.2.1 and earlier allows remote attackers to modify system configuration via unknown attack vectophprojekt · phprojekt · CWE-264 | Yüksek7,5 | — | %1,7 | 31 Ara 2004 |
30İzleyin | CVE-2002-1760İstismar yok | Multiple SQL injection vulnerabilities in PHProjekt 2.0 through 3.1 allow remote attackers to execute arbitrary SQL commands via the unknownphprojekt · phprojekt | Yüksek7,5 | — | %1,2 | 31 Ara 2002 |
21İzleyin | CVE-2001-0648İstismar yok | Directory traversal vulnerability in PHProjekt 2.1 and earlier allows a remote attacker to conduct unauthorized activities via a dot dot (..phprojekt · phprojekt | Orta5,0 | — | %2,3 | 20 Eyl 2001 |
21İzleyin | CVE-2002-1759İstismar yok | The upload function in PHProjekt 2.0 through 3.1 does not properly verify certain variables related to uploaded data, which allows remote atphprojekt · phprojekt | Orta5,0 | — | %2,1 | 31 Ara 2002 |
21İzleyin | CVE-2002-1758İstismar yok | PHProjekt 2.0 through 3.1 allows remote attackers to view or modify data via requests to certain scripts that do not verify if the user is lphprojekt · phprojekt | Orta5,0 | — | %2,1 | 31 Ara 2002 |
20İzleyin | CVE-2002-1761İstismar yok | Directory traversal vulnerability in PHProjekt 2.0 through 3.1 allows remote attackers to read arbitrary files via ..phprojekt · phprojekt | Orta5,0 | — | %1,5 | 31 Ara 2002 |
20İzleyin | CVE-2005-1227İstismar yok | Cross-site scripting (XSS) vulnerability in PHProjekt 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via thephprojekt · phprojekt | Orta5,1 | — | %1,5 | 20 Nis 2005 |
20İzleyin | CVE-2011-3786İstismar yok | PHProjekt 6.0.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation phprojekt · phprojekt · CWE-200 | Orta5,0 | — | %1,2 | 23 Eyl 2011 |
18İzleyin | CVE-2007-1576İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users phprojekt · phprojekt · CWE-79 | Orta4,3 | — | %1,8 | 21 Mar 2007 |
17İzleyin | CVE-2004-2740İstismar yok | PHP remote file inclusion vulnerability in authform.inc.php in PHProjekt 4.2.3 and earlier allows remote attackers to include arbitrary PHP phprojekt · phprojekt · CWE-94 | Orta4,3 | — | %1,5 | 31 Ara 2004 |
- CVE-2006-420432İzleyin
Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execute arbitrary PHP cod
YüksekCVSS 7,5Kavram kanıtıEPSS %8phprojekt · phprojekt17 Ağu 2006
- CVE-2002-175731İzleyin
PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for sc
YüksekCVSS 7,5Kavram kanıtıEPSS %3phprojekt · phprojekt31 Ara 2002
- CVE-2006-512331İzleyin
Multiple PHP remote file inclusion vulnerabilities in Albrecht Guenther PHProjekt 5.1.x before 5.1.2 allow remote attackers to execute arbit
YüksekCVSS 7,5İstismar yokEPSS %2phprojekt · phprojekt3 Eki 2006
- CVE-2007-157531İzleyin
Multiple SQL injection vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to execute ar
YüksekCVSS 7,5İstismar yokEPSS %2phprojekt · phprojekt21 Mar 2007
- CVE-2004-273931İzleyin
The setup routine (setup.php) in PHProjekt 4.2.1 and earlier allows remote attackers to modify system configuration via unknown attack vecto
YüksekCVSS 7,5İstismar yokEPSS %2phprojekt · phprojekt31 Ara 2004
- CVE-2002-176030İzleyin
Multiple SQL injection vulnerabilities in PHProjekt 2.0 through 3.1 allow remote attackers to execute arbitrary SQL commands via the unknown
YüksekCVSS 7,5İstismar yokEPSS %1phprojekt · phprojekt31 Ara 2002
- CVE-2001-064821İzleyin
Directory traversal vulnerability in PHProjekt 2.1 and earlier allows a remote attacker to conduct unauthorized activities via a dot dot (..
OrtaCVSS 5,0İstismar yokEPSS %2phprojekt · phprojekt20 Eyl 2001
- CVE-2002-175921İzleyin
The upload function in PHProjekt 2.0 through 3.1 does not properly verify certain variables related to uploaded data, which allows remote at
OrtaCVSS 5,0İstismar yokEPSS %2phprojekt · phprojekt31 Ara 2002
- CVE-2002-175821İzleyin
PHProjekt 2.0 through 3.1 allows remote attackers to view or modify data via requests to certain scripts that do not verify if the user is l
OrtaCVSS 5,0İstismar yokEPSS %2phprojekt · phprojekt31 Ara 2002
- CVE-2002-176120İzleyin
Directory traversal vulnerability in PHProjekt 2.0 through 3.1 allows remote attackers to read arbitrary files via ..
OrtaCVSS 5,0İstismar yokEPSS %1phprojekt · phprojekt31 Ara 2002
- CVE-2005-122720İzleyin
Cross-site scripting (XSS) vulnerability in PHProjekt 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the
OrtaCVSS 5,1İstismar yokEPSS %1phprojekt · phprojekt20 Nis 2005
- CVE-2011-378620İzleyin
PHProjekt 6.0.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
OrtaCVSS 5,0İstismar yokEPSS %1phprojekt · phprojekt23 Eyl 2011
- CVE-2007-157618İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users
OrtaCVSS 4,3İstismar yokEPSS %2phprojekt · phprojekt21 Mar 2007
- CVE-2004-274017İzleyin
PHP remote file inclusion vulnerability in authform.inc.php in PHProjekt 4.2.3 and earlier allows remote attackers to include arbitrary PHP
OrtaCVSS 4,3İstismar yokEPSS %1phprojekt · phprojekt31 Ara 2004