Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpkit phpkit 1.6.1 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2005-4424
Directory traversal vulnerability in PHPKIT 1.6.1 R2 and previous versions might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the path parameter and a %00 at the end of the filename, as demonstrated by an avatar filename ending with .png%00...
Phpkit Phpkit 1.6.02
Phpkit Phpkit 1.6.1
Phpkit Phpkit 1.6.03
NA
CVE-2005-3554
Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and previous versions, when register_globals is enabled, allow remote malicious users to execute arbitrary code on the server via unknown attack vectors involving uninitialized variables.
Phpkit Phpkit 1.6.02
Phpkit Phpkit 1.6.1
Phpkit Phpkit 1.6.03
NA
CVE-2004-1537
Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 up to and including 1.6.1 allows remote malicious users to execute arbitrary web script via the img parameter.
Phpkit Phpkit 1.6.02
Phpkit Phpkit 1.6.03
Phpkit Phpkit 1.6.1
1 EDB exploit
NA
CVE-2004-1538
SQL injection vulnerability in include.php in PHPKIT 1.6.03 up to and including 1.6.1 allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Phpkit Phpkit 1.6.02
Phpkit Phpkit 1.6.03
Phpkit Phpkit 1.6.1
NA
CVE-2007-0179
SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote malicious users to execute arbitrary SQL commands via the subid parameter.
Phpkit Phpkit 1.6.1
1 EDB exploit
NA
CVE-2005-2699
Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a .php file to the content/images/ directory using images.php. NOTE: if a PHPKit administrator must already have access ...
Phpkit Phpkit 1.6.1
NA
CVE-2006-7115
SQL injection vulnerability in PHPKit 1.6.1 RC2 allows remote malicious users to inject arbitrary SQL commands via the catid parameter to include.php when the path parameter is set to faq/faq.php, and other unspecified vectors involving guestbook/print.php.
Phpkit Phpkit 1.6.1
NA
CVE-2005-2683
Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote malicious users to execute arbitrary SQL commands via the (1) letter parameter to login/member.php or (2) im_receiver parameter to login/imcenter.php.
Phpkit Phpkit 1.6.1
1 EDB exploit
NA
CVE-2006-1773
SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and previous versions allows remote malicious users to execute arbitrary SQL commands via the contentid parameter, possibly involving content/news.php.
Phpkit Phpkit
1 EDB exploit
NA
CVE-2005-3553
Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) id parameter in conjunction with the login/userinfo.php path and (2) the session parameter (aka the PHPKITSID ...
Phpkit Phpkit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
administrator privileges
CVE-2024-1579
hardcoded
CVE-2023-20198
CVE-2024-33587
CVE-2024-33449
CVE-2024-4308
HTML injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »