Phpstatus
Hinton Design · 3 CVEs
CVE-2006-0572
HIGH
phpstatus 1.0 does not require passwords when using cookies to identify a user, which allows remote attackers to bypass…
Feb 7, 2006
CVE-2006-0571
MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in phpstatus 1.0 allow remote attackers to inject arbitrary web scr…
Feb 7, 2006
CVE-2006-0570
HIGH
Multiple SQL injection vulnerabilities in phpstatus 1.0, when gpc_magic_quotes is disabled, allow remote attackers to e…
Feb 7, 2006
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2006-0572 | phpstatus 1.0 does not require passwords when using cookies to identify a user, which allows remote attackers to bypass authentication. | HIGH | 1.68% | Feb 7, 2006 |
| CVE-2006-0571 | Multiple cross-site scripting (XSS) vulnerabilities in phpstatus 1.0 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors i… | MEDIUM | 1.33% | Feb 7, 2006 |
| CVE-2006-0570 | Multiple SQL injection vulnerabilities in phpstatus 1.0, when gpc_magic_quotes is disabled, allow remote attackers to execute arbitrary SQL commands and bypass… | HIGH | 1.45% | Feb 7, 2006 |
Showing 1 to 3 of 3 CVEs