Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
php-stats php-stats vulnerabilities and exploits
(subscribe to this query)
760
VMScore
CVE-2006-7172
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and previous versions allow remote malicious users to execute arbitrary code via a leading dotted-quad IP address string in the (1) PC-REMOTE-ADDR HTTP header, which is inserted into $_SERVER[...
Php-stats Php-stats
2 EDB exploits
1000
VMScore
CVE-2006-7173
Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and previous versions allows remote malicious users to execute arbitrary PHP code via a crafted option_new[report_w_day] parameter in a preferenze action, which can be later accessed via option/php-stat...
Php-stats Php-stats
1 EDB exploit
445
VMScore
CVE-2006-1088
PHP-Stats 0.1.9.1 and previous versions allows remote malicious users to obtain potentially sensitive information via a direct request to checktables.php, which lists the database table_prefix.
Php-stats Php-stats
668
VMScore
CVE-2006-1084
Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and previous versions allow remote malicious users to execute arbitrary SQL commands via (1) the option[prefix] parameter in admin.php and other unspecified PHP scripts, and (2) the PC_REMOTE_ADDR HTTP header to click.ph...
Php-stats Php-stats
890
VMScore
CVE-2006-1085
admin.php in PHP-Stats 0.1.9.1 and previous versions allows remote malicious users to bypass authentication, gain administrator privileges, and execute arbitrary PHP code by modifying the option[admin_pass] parameter and setting the pass_cookie to the MD5 hash of the specified pa...
Php-stats Php-stats
578
VMScore
CVE-2006-1087
Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and previous versions allows remote authenticated administrators to execute arbitrary PHP code via the option_new[compatibility_mode] parameter, which is not filtered before ...
Php-stats Php-stats
668
VMScore
CVE-2006-1083
Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and previous versions allow remote malicious users to read and possibly execute arbitrary files via a .. (dot dot) in the (1) option[language] and (2) option[template] parameters, and (3) possibly other parameters,...
Php-stats Php-stats
435
VMScore
CVE-2007-4917
Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote malicious users to inject arbitrary web script or HTML via the ip parameter in an online action, a different vector than CVE-2007-4334.
Php-stats Php-stats 0.1.9.2
1 EDB exploit
1000
VMScore
CVE-2007-5452
Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote malicious users to execute arbitrary SQL commands via the (1) ip or (2) t parameter.
Php-stats Php-stats 0.1.9.2
1 EDB exploit
435
VMScore
CVE-2007-4334
Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote malicious users to inject arbitrary web script or HTML via the IP parameter.
Php-stats Php-stats 0.1.9.2
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2006-4304
CVE-2024-4240
arbitrary
CVE-2024-31601
XSS
CVE-2023-20198
CVE-2024-4256
CVE-2024-3342
encryption
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »