Coinsoft Technologies / Phpcoin
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2006-4425 | Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 allow remote attackers to execute arbitrary PHP code via the _CCFG[_PKG_PATH_INCL] paramete… | MEDIUM | 5.1 | Aug 29, 2006 |
| CVE-2006-4424 | PHP remote file inclusion vulnerability in coin_includes/constants.php in phpCOIN 1.2.3 allows remote attackers to execute arbitrary PHP code via the _CCFG[_PK… | MEDIUM | 5.1 | Aug 29, 2006 |
| CVE-2006-2422 | phpCOIN 1.2.3 and earlier stores messages based upon e-mail addresses, which allows remote authenticated users to read messages for other users by adding the s… | MEDIUM | 5.0 | May 17, 2006 |
| CVE-2006-1428 | Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs param… | MEDIUM | 4.3 | Mar 28, 2006 |
| CVE-2005-4214 | phpCOIN 1.2.2 allows remote attackers to obtain the installation path via a direct request to config.php, which leaks the path in an error message because the… | MEDIUM | 5.0 | Dec 14, 2005 |
| CVE-2005-4213 | SQL injection vulnerability in mod.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary SQL commands via the phpcoinsessid cookie. | HIGH | 7.5 | Dec 14, 2005 |
| CVE-2005-4212 | Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) sequences i… | MEDIUM | 5.0 | Dec 14, 2005 |
| CVE-2005-4211 | PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the $_CCFG[… | HIGH | 7.5 | Dec 14, 2005 |
| CVE-2005-1384 | Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index.php, (2)… | HIGH | 7.5 | May 2, 2005 |
| CVE-2005-0947 | Directory traversal vulnerability in auxpage.php in phpCoin 1.2.1b and earlier allows remote attackers to read and execute arbitrary files via a .. (dot dot) i… | HIGH | 7.5 | Apr 3, 2005 |
| CVE-2005-0946 | SQL injection vulnerability in phpCoin 1.2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the (1) term/keywords field on the sear… | HIGH | 7.5 | Apr 3, 2005 |
| CVE-2005-0933 | Directory traversal vulnerability in auxpage.php for phpCOIN 1.2.1b and earlier allows remote attackers to read arbitrary files via the page parameter. | MEDIUM | 5.0 | Mar 29, 2005 |
| CVE-2005-0932 | Multiple SQL injection vulnerabilities in phpCOIN 1.2.1b and earlier allow remote attackers to execute arbitrary SQL commands (1) via the search engine, (2) th… | HIGH | 7.5 | Mar 29, 2005 |
| CVE-2005-0670 | Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web script or HTML via (1) the new paramet… | MEDIUM | 4.3 | Mar 7, 2005 |
| CVE-2005-0669 | Multiple SQL injection vulnerabilities in mod.php for phpCOIN 1.2.0 through 1.2.1b allow remote attackers to execute arbitrary SQL commands via the (1) the faq… | HIGH | 7.5 | Mar 7, 2005 |
Showing 1 to 15 of 15 CVEs