VYPR

Phpmyfaq

by PhpMyAdmin

Source repositories

CVEs (170)

  • CVE-2007-1032Feb 21, 2007
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploading files on the server."

  • CVE-2006-6913Dec 31, 2006
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to upload arbitrary PHP scripts via unspecified vectors.

  • CVE-2005-3734Nov 22, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the "add content" page in phpMyFAQ 1.5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) thema, (2) username, and (3) usermail parameters.

  • CVE-2005-3046Sep 24, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.

  • CVE-2005-3050Sep 24, 2005
    risk 0.00cvss epss 0.01

    PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message.

  • CVE-2005-3047Sep 24, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php.

  • CVE-2005-3049Sep 24, 2005
    risk 0.00cvss epss 0.03

    PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file.

  • CVE-2005-0702Mar 7, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.

  • CVE-2004-2255Dec 31, 2004
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename.

  • CVE-2004-2256Dec 31, 2004
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable.

Page 9 of 9