Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpkit phpkit 1.6.03 vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2003-1187
Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote malicious users to inject arbitrary web script or HTML via the contact_email parameter.
Phpkit Phpkit 1.6.02
Phpkit Phpkit 1.6.03
1 EDB exploit
6.5
CVSSv2
CVE-2005-4424
Directory traversal vulnerability in PHPKIT 1.6.1 R2 and previous versions might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the path parameter and a %00 at the end of the filename, as demonstrated by an avatar filename ending with .png%00...
Phpkit Phpkit 1.6.02
Phpkit Phpkit 1.6.1
Phpkit Phpkit 1.6.03
7.5
CVSSv2
CVE-2004-1538
SQL injection vulnerability in include.php in PHPKIT 1.6.03 up to and including 1.6.1 allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Phpkit Phpkit 1.6.02
Phpkit Phpkit 1.6.03
Phpkit Phpkit 1.6.1
5.1
CVSSv2
CVE-2005-3554
Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and previous versions, when register_globals is enabled, allow remote malicious users to execute arbitrary code on the server via unknown attack vectors involving uninitialized variables.
Phpkit Phpkit 1.6.02
Phpkit Phpkit 1.6.1
Phpkit Phpkit 1.6.03
4.3
CVSSv2
CVE-2004-1537
Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 up to and including 1.6.1 allows remote malicious users to execute arbitrary web script via the img parameter.
Phpkit Phpkit 1.6.02
Phpkit Phpkit 1.6.03
Phpkit Phpkit 1.6.1
1 EDB exploit
4.3
CVSSv2
CVE-2004-1879
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote malicious users to inject arbitrary web script or HTML via forum messages.
Phpkit Phpkit 1.6.03
6.8
CVSSv2
CVE-2006-1507
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote malicious users to inject arbitrary web script or HTML via the error parameter to include.php, possibly due to a problem in login/login.php.
Phpkit Phpkit 1.6.03
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32976
CVE-2024-33557
CVE-2024-36801
CVE-2024-35654
authentication bypass
CVE-2024-24919
CSRF
code execution
CVE-2024-27348
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started