VYPR

Phpmyfaq

by PhpMyAdmin

Source repositories

CVEs (192)

  • CVE-2009-4780Apr 21, 2010
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in phpMyFAQ before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter in a sitemap action, (2) the search parameter in a search action, (3) the tagging_id parameter in a…

  • CVE-2009-4040Nov 20, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page.

  • CVE-2007-1032Feb 21, 2007
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploading files on the server."

  • CVE-2006-6913Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to upload arbitrary PHP scripts via unspecified vectors.

  • CVE-2005-3734Nov 22, 2005
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the "add content" page in phpMyFAQ 1.5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) thema, (2) username, and (3) usermail parameters.

  • CVE-2005-3049Sep 24, 2005
    risk 0.00cvss —epss 0.03

    PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file.

  • CVE-2005-3046Sep 24, 2005
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.

  • CVE-2005-3047Sep 24, 2005
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php.

  • CVE-2005-3050Sep 24, 2005
    risk 0.00cvss —epss 0.01

    PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message.

  • CVE-2005-0702Mar 7, 2005
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.

  • CVE-2004-2256Dec 31, 2004
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable.

  • CVE-2004-2255Dec 31, 2004
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename.

Page 10 of 10