PHP Arena / Pafiledb
21 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2007-3808 | SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categories[] parameter in… | HIGH | 7.5 | Jul 17, 2007 |
| CVE-2006-2361 | PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers… | HIGH | 7.5 | May 15, 2006 |
| CVE-2005-4329 | SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitrary SQL commands vi… | HIGH | 7.5 | Dec 17, 2005 |
| CVE-2005-2723 | SQL injection vulnerability in auth.php in PaFileDB 3.1, when authmethod is set to cookies, allows remote attackers to execute arbitrary SQL commands via the u… | HIGH | 7.5 | Aug 29, 2005 |
| CVE-2002-1931 | Cross-site scripting (XSS) vulnerability in PHP Arena paFileDB 1.1.3 and 2.1.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in… | MEDIUM | 4.3 | Jun 28, 2005 |
| CVE-2002-1929 | Cross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena paFileDB 1.1.3 through 3.0 allows remote attackers to inject arbitrary web script or HTML… | MEDIUM | 4.3 | Jun 28, 2005 |
| CVE-2005-2001 | Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the acti… | MEDIUM | 5.0 | Jun 20, 2005 |
| CVE-2005-2000 | Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in t… | HIGH | 7.5 | Jun 20, 2005 |
| CVE-2005-1999 | Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s… | MEDIUM | 4.3 | Jun 20, 2005 |
| CVE-2004-1975 | Cross-site scripting (XSS) vulnerability in the category module in pafiledb.php for paFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML… | MEDIUM | 4.3 | May 10, 2005 |
| CVE-2004-1974 | paFileDB 3.1 allows remote attackers to gain sensitive information via a direct request to (1) login.php, (2) category.php, (3) search.php, (4) main.php, (5) v… | MEDIUM | 5.0 | May 10, 2005 |
| CVE-2005-0952 | Cross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | MEDIUM | 5.0 | Apr 3, 2005 |
| CVE-2005-0782 | Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web s… | MEDIUM | 4.3 | Mar 20, 2005 |
| CVE-2005-0781 | SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via t… | HIGH | 7.5 | Mar 20, 2005 |
| CVE-2005-0780 | paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) fil… | MEDIUM | 5.0 | Mar 20, 2005 |
| CVE-2005-0724 | paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via (1) an invalid str parameter to pafiledb.php, or a direct request to (2) v… | MEDIUM | 5.0 | Mar 12, 2005 |
| CVE-2005-0723 | Cross-site scripting (XSS) vulnerability in the jumpmenu function in functions.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web… | MEDIUM | 4.3 | Mar 12, 2005 |
| CVE-2004-1551 | Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web script or… | MEDIUM | 4.3 | Feb 20, 2005 |
| CVE-2005-0327 | pafiledb.php in Pafiledb 3.1 may allow remote attackers to execute arbitrary PHP code via a modified action parameter that is used in an include statement for… | HIGH | 7.5 | Feb 10, 2005 |
| CVE-2005-0326 | pafiledb.php in PaFileDB 3.1 allows remote attackers to gain sensitive information via an invalid or missing action parameter, which reveals the path in an err… | MEDIUM | 5.0 | Feb 10, 2005 |
| CVE-2004-1219 | paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's password hash and con… | MEDIUM | 5.0 | Dec 15, 2004 |
Showing 1 to 21 of 21 CVEs