Pafaq
PHP Arena · 5 CVEs
CVE-2005-2014
MEDIUM
The "upload a language pack" feature in paFAQ 1.0 Beta 4 allows remote authenticated administrators to execute arbitrar…
Jun 20, 2005
CVE-2005-2013
MEDIUM
paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, whic…
Jun 20, 2005
CVE-2005-2012
HIGH
Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL com…
Jun 20, 2005
CVE-2005-2011
MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web…
Jun 20, 2005
CVE-2005-0475
MEDIUM
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary S…
Feb 19, 2005
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2005-2014 | The "upload a language pack" feature in paFAQ 1.0 Beta 4 allows remote authenticated administrators to execute arbitrary PHP commands by uploading a malicious… | MEDIUM | 0.65% | Jun 20, 2005 |
| CVE-2005-2013 | paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, which contains a backup of the database incl… | MEDIUM | 1.34% | Jun 20, 2005 |
| CVE-2005-2012 | Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the… | HIGH | 1.19% | Jun 20, 2005 |
| CVE-2005-2011 | Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the… | MEDIUM | 1.42% | Jun 20, 2005 |
| CVE-2005-0475 | SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (… | MEDIUM | 1.01% | Feb 19, 2005 |
Showing 1 to 5 of 5 CVEs