Phpadsnew / Phpadsnew
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2007-0486 | Multiple PHP remote file inclusion vulnerabilities in Openads (aka phpAdsNew) 2.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) p… | HIGH | 7.5 | Jan 25, 2007 |
| CVE-2006-6415 | PHP remote file inclusion vulnerability in admin/lib-maintenance.inc.php in phpAdsNew 2.0.4-pr2 allows remote attackers to execute arbitrary PHP code via a URL… | HIGH | 7.5 | Dec 10, 2006 |
| CVE-2006-5515 | Cross-site scripting (XSS) vulnerability in lib-history.inc.php in phpAdsNew and phpPgAds before 2.0.8-pr1 allows remote attackers to inject arbitrary web scri… | MEDIUM | 4.3 | Oct 26, 2006 |
| CVE-2006-5437 | Directory traversal vulnerability in upgrade.php in phpAdsNew 2.0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the phpAds_config[lan… | MEDIUM | 5.0 | Oct 20, 2006 |
| CVE-2006-3984 | PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later versions, with phpAdsNew 2.0.5, allows remo… | HIGH | 7.5 | Aug 5, 2006 |
| CVE-2006-1397 | Multiple cross-site scripting (XSS) vulnerabilities in (a) phpAdsNew and (b) phpPgAds before 2.0.8 allow remote attackers to inject arbitrary web script or HTM… | MEDIUM | 4.3 | Mar 28, 2006 |
| CVE-2005-3791 | HTTP response splitting vulnerability in phpAdsNew and phpPgAds 2.0.6 and earlier allows remote attackers to inject arbitrary HTML headers via adclick.php and… | MEDIUM | 5.0 | Nov 24, 2005 |
| CVE-2005-3646 | Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote attackers to execute… | HIGH | 7.5 | Nov 17, 2005 |
| CVE-2005-3645 | phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allows remote attackers to obtain the application installation path and other sensitive information… | MEDIUM | 5.0 | Nov 17, 2005 |
| CVE-2005-2636 | SQL injection vulnerability in lib-view-direct.inc.php in phpAdsNew and phpPgAds before 2.0.6 allows remote attackers to execute arbitrary SQL commands via the… | HIGH | 7.5 | Aug 20, 2005 |
| CVE-2005-2635 | Multiple directory traversal vulnerabilities in phpAdsNew and phpPgAds before 2.0.6 allow remote attackers to include arbitrary files via a .. (dot dot) in the… | MEDIUM | 5.0 | Aug 20, 2005 |
| CVE-2005-0790 | phpAdsNew 2.0.4 allows remote attackers to obtain sensitive information via a direct request to (1) lib-xmlrpcs.inc.php, (2) maintenance-activation.php, (3) ma… | MEDIUM | 5.0 | Mar 20, 2005 |
| CVE-2001-1054 | PHPAdsNew PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | HIGH | 7.5 | Mar 9, 2002 |
Showing 1 to 13 of 13 CVEs