Ptk
Dflabs · 6 CVEs
Cross-site request forgery (CSRF) vulnerability in lib/logout.php in DFLabs PTK 1.0.5 and earlier allows remote attacke…
Dec 28, 2014
Cross-site scripting (XSS) vulnerability in ptk/lib/modal_bookmark.php in DFLabs PTK 1.0.5 allows remote attackers to i…
Nov 17, 2012
DFLabs PTK 1.0.5 stores data files with predictable names under the web document root with insufficient access control,…
Nov 17, 2012
The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute a…
May 7, 2009
Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary comm…
Mar 16, 2009
Cross-site scripting (XSS) vulnerability in DFLabs PTK 1.0.0 through 1.0.4 allows remote attackers to inject arbitrary…
Mar 16, 2009
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2012-1415 | Cross-site request forgery (CSRF) vulnerability in lib/logout.php in DFLabs PTK 1.0.5 and earlier allows remote attackers to hijack the authentication of admin… | MEDIUM | 1.06% | Dec 28, 2014 |
| CVE-2012-5902 | Cross-site scripting (XSS) vulnerability in ptk/lib/modal_bookmark.php in DFLabs PTK 1.0.5 allows remote attackers to inject arbitrary web script or HTML via t… | MEDIUM | 1.16% | Nov 17, 2012 |
| CVE-2012-5901 | DFLabs PTK 1.0.5 stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers to read l… | MEDIUM | 1.37% | Nov 17, 2012 |
| CVE-2008-6793 | The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute arbitrary commands via shell metacharacte… | MEDIUM | 6.93% | May 7, 2009 |
| CVE-2009-0918 | Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apac… | HIGH | 2.73% | Mar 16, 2009 |
| CVE-2009-0917 | Cross-site scripting (XSS) vulnerability in DFLabs PTK 1.0.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML by providing a forens… | MEDIUM | 1.54% | Mar 16, 2009 |
Showing 1 to 6 of 6 CVEs