Phpmyfaq
by PhpMyAdmin
Source repositories
CVEs (170)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2007-1032 | 0.00 | — | 0.01 | Feb 21, 2007 | Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploading files on the server." | |||
| CVE-2006-6913 | 0.00 | — | 0.01 | Dec 31, 2006 | Unspecified vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to upload arbitrary PHP scripts via unspecified vectors. | |||
| CVE-2005-3734 | 0.00 | — | 0.01 | Nov 22, 2005 | Cross-site scripting (XSS) vulnerability in the "add content" page in phpMyFAQ 1.5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) thema, (2) username, and (3) usermail parameters. | |||
| CVE-2005-3046 | 0.00 | — | 0.01 | Sep 24, 2005 | SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field. | |||
| CVE-2005-3050 | 0.00 | — | 0.01 | Sep 24, 2005 | PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message. | |||
| CVE-2005-3047 | 0.00 | — | 0.01 | Sep 24, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php. | |||
| CVE-2005-3049 | 0.00 | — | 0.03 | Sep 24, 2005 | PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file. | |||
| CVE-2005-0702 | 0.00 | — | 0.01 | Mar 7, 2005 | SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages. | |||
| CVE-2004-2255 | 0.00 | — | 0.02 | Dec 31, 2004 | Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename. | |||
| CVE-2004-2256 | 0.00 | — | 0.02 | Dec 31, 2004 | Directory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable. |
- CVE-2007-1032Feb 21, 2007risk 0.00cvss —epss 0.01
Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploading files on the server."
- CVE-2006-6913Dec 31, 2006risk 0.00cvss —epss 0.01
Unspecified vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to upload arbitrary PHP scripts via unspecified vectors.
- CVE-2005-3734Nov 22, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the "add content" page in phpMyFAQ 1.5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) thema, (2) username, and (3) usermail parameters.
- CVE-2005-3046Sep 24, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.
- CVE-2005-3050Sep 24, 2005risk 0.00cvss —epss 0.01
PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message.
- CVE-2005-3047Sep 24, 2005risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php.
- CVE-2005-3049Sep 24, 2005risk 0.00cvss —epss 0.03
PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file.
- CVE-2005-0702Mar 7, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.
- CVE-2004-2255Dec 31, 2004risk 0.00cvss —epss 0.02
Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename.
- CVE-2004-2256Dec 31, 2004risk 0.00cvss —epss 0.02
Directory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable.
Page 9 of 9