Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
php arena pafaq 1.0 beta 4 vulnerabilities and exploits
(subscribe to this query)
409
VMScore
CVE-2005-2014
The "upload a language pack" feature in paFAQ 1.0 Beta 4 allows remote authenticated administrators to execute arbitrary PHP commands by uploading a malicious language pack.
Php Arena Pafaq 1.0 Beta 4
445
VMScore
CVE-2005-2013
paFAQ 1.0 Beta 4 allows remote malicious users to obtain sensitive information via a direct request to admin/backup.php, which contains a backup of the database including usernames and passwords.
Php Arena Pafaq 1.0 Beta 4
755
VMScore
CVE-2005-2012
Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote malicious users to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) id parameters.
Php Arena Pafaq 1.0 Beta 4
1 EDB exploit
435
VMScore
CVE-2005-2011
Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote malicious users to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Question action.
Php Arena Pafaq 1.0 Beta 4
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started