CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2016-10758 HIGH

PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_name paramet…

CVSS 8.8 EPSS 1.62% May 24, 2019
CVE-2015-1052 MEDIUM

Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT 1.6.6 (Build 160014) allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 EPSS 1.89% Jan 15, 2015
CVE-2008-7193 MEDIUM

PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by reading the PHPKITSI…

CVSS 6.8 EPSS 0.57% Sep 9, 2009
CVE-2007-6134 HIGH

SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via the contentid paramete…

CVSS 7.5 EPSS 1.09% Nov 27, 2007
CVE-2006-7115 HIGH

SQL injection vulnerability in PHPKit 1.6.1 RC2 allows remote attackers to inject arbitrary SQL commands via the catid parameter to include.php when the path p…

CVSS 7.5 EPSS 1.39% Mar 6, 2007
CVE-2007-0179 HIGH

SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parameter.

CVSS 7.5 EPSS 1.06% Jan 11, 2007
CVE-2006-1773 MEDIUM

SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands via the contentid pa…

CVSS 6.4 EPSS 1.14% Apr 13, 2006
CVE-2006-1507 MEDIUM

Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error parameter to include.php…

CVSS 6.8 EPSS 1.46% Mar 30, 2006
CVE-2006-0786 MEDIUM

Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackers to conduct PHP r…

CVSS 5.1 EPSS 2.42% Feb 19, 2006
CVE-2006-0785 MEDIUM

Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arbitrary local files…

CVSS 6.4 EPSS 1.62% Feb 19, 2006
CVE-2005-4424 MEDIUM

Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the…

CVSS 6.5 EPSS 1.72% Dec 20, 2005
CVE-2005-3554 MEDIUM

Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote attackers to execut…

CVSS 5.1 EPSS 3.41% Nov 16, 2005
CVE-2005-3553 HIGH

Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id pa…

CVSS 7.5 EPSS 1.94% Nov 16, 2005
CVE-2005-3552 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple v…

CVSS 4.3 EPSS 1.95% Nov 16, 2005
CVE-2005-2699 MEDIUM

Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading…

CVSS 4.6 EPSS 0.48% Aug 25, 2005
CVE-2005-2683 HIGH

Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to login/member.ph…

CVSS 7.5 EPSS 2.41% Aug 23, 2005
CVE-2004-1879 MEDIUM

Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum messages.

CVSS 4.3 EPSS 1.20% May 10, 2005
CVE-2003-1187 MEDIUM

Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the cont…

CVSS 6.8 EPSS 4.22% May 10, 2005
CVE-2004-1538 HIGH

SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 EPSS 1.33% Feb 19, 2005
CVE-2004-1537 MEDIUM

Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script via the img parame…

CVSS 4.3 EPSS 1.75% Feb 19, 2005

Showing 1 to 20 CVEs · page 1