Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpwcms phpwcms vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2006-6886
phpwcms 1.2.5-DEV allows remote malicious users to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.private.additions.inc.php in include/inc_lib/, which reveals the path in various error messages.
Phpwcms Phpwcms 1.2.5 Dev
6.1
CVSSv3
CVE-2020-19855
phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.
Phpwcms Phpwcms 1.9.0
5.3
CVSSv3
CVE-2018-12990
phpwcms 1.8.9 allows remote malicious users to discover the installation path via an invalid csrf_token_value field.
Phpwcms Phpwcms 1.8.9
NA
CVE-2005-3789
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote malicious users to read arbitrary files via a .. (dot dot) in the (1) form_lang parameter in login.php and (2) the imgdir parameter in random_image.php.
Phpwcms Phpwcms 1.2.5 Dev
2 EDB exploits
4.8
CVSSv3
CVE-2017-15872
phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_login) field.
Phpwcms Phpwcms 1.8.9
NA
CVE-2007-5185
Multiple PHP remote file inclusion vulnerabilities in phpWCMS XT 0.0.7 BETA and previous versions allow remote malicious users to execute arbitrary PHP code via a URL in the HTML_MENU_DirPath parameter to (1) config_HTML_MENU.php and (2) config_PHPLM.php in phpwcms_template/inc_s...
Phpwcms-xt Phpwcms-xt
1 EDB exploit
NA
CVE-2006-7018
phpwcms 1.2.5-DEV and previous versions, and 1.1 before RC4, allows remote malicious users to execute arbitrary code via a crafted argument to the nome_evento parameter to phpwcms_code_snippets/mail_file_form.php and (2) sample_ext_php/mail_file_form.php, which is processed by th...
Oliver Georgi Phpwcms
NA
CVE-2006-7020
CRLF injection vulnerability in (1) include/inc_act/act_formmailer.php and possibly (2) sample_ext_php/mail_file_form.php in phpwcms 1.2.5-DEV and previous versions, and 1.1 before RC4, allows remote malicious users to modify HTTP headers and send spam e-mail via a spoofed HTTP R...
Oliver Georgi Phpwcms
9.8
CVSSv3
CVE-2013-1744
IRIS citations management tool up to and including 1.3 allows remote malicious users to execute arbitrary commands.
Iris Citations Management Tool Project Iris Citations Management Tool
1 EDB exploit
NA
CVE-2005-3790
Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote malicious users to inject arbitrary web script or HTML via the (1) i and (2) text parameters.
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2