Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
php arena pafaq 1.0 beta 4 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2005-2014
The "upload a language pack" feature in paFAQ 1.0 Beta 4 allows remote authenticated administrators to execute arbitrary PHP commands by uploading a malicious language pack.
Php Arena Pafaq 1.0 Beta 4
NA
CVE-2005-2013
paFAQ 1.0 Beta 4 allows remote malicious users to obtain sensitive information via a direct request to admin/backup.php, which contains a backup of the database including usernames and passwords.
Php Arena Pafaq 1.0 Beta 4
NA
CVE-2005-2012
Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote malicious users to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) id parameters.
Php Arena Pafaq 1.0 Beta 4
1 EDB exploit
NA
CVE-2005-2011
Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote malicious users to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Question action.
Php Arena Pafaq 1.0 Beta 4
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started