Vwar / Virtual War
22 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2010-5279 | article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to cause a denial of service (memory consumption) via a large integer in the ratearticle… | MEDIUM | 5.0 | Oct 8, 2012 |
| CVE-2010-5067 | Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for remote attackers to bypass timeout… | MEDIUM | 6.8 | Oct 8, 2012 |
| CVE-2010-5066 | The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to select the seed argument… | MEDIUM | 4.3 | Oct 8, 2012 |
| CVE-2010-5065 | popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news posts via a modified newsid parameter… | MEDIUM | 5.0 | Oct 8, 2012 |
| CVE-2010-5064 | Multiple cross-site scripting (XSS) vulnerabilities in Virtual War (aka VWar) 1.6.1 R2 allow remote attackers to inject arbitrary web script or HTML via (1) th… | MEDIUM | 4.3 | Oct 8, 2012 |
| CVE-2010-5063 | SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the ratearticlesele… | HIGH | 7.5 | Oct 8, 2012 |
| CVE-2011-3813 | Virtual War (aka VWar) 1.5.0r15 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pat… | MEDIUM | 5.0 | Sep 24, 2011 |
| CVE-2008-0753 | SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter. | HIGH | 7.5 | Feb 13, 2008 |
| CVE-2007-4605 | PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute arbitrary PHP code v… | HIGH | 7.5 | Aug 31, 2007 |
| CVE-2007-2312 | Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the… | HIGH | 7.5 | Apr 26, 2007 |
| CVE-2007-2306 | Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allo… | MEDIUM | 4.3 | Apr 26, 2007 |
| CVE-2006-4224 | Cross-site scripting (XSS) vulnerability in calendar.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML… | MEDIUM | 4.3 | Aug 18, 2006 |
| CVE-2006-4142 | SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQL commands via the n… | HIGH | 7.5 | Aug 14, 2006 |
| CVE-2006-4141 | SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) sortby an… | HIGH | 7.5 | Aug 14, 2006 |
| CVE-2006-4010 | SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter… | HIGH | 7.5 | Aug 7, 2006 |
| CVE-2006-4009 | Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via… | MEDIUM | 4.3 | Aug 7, 2006 |
| CVE-2006-3139 | Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQL commands via the… | HIGH | 7.5 | Jun 22, 2006 |
| CVE-2006-2091 | admin.php in Virtual War (VWar) 1.5 and versions before 1.2 allows remote attackers to obtain sensitive information via an invalid vwar_root parameter, which r… | MEDIUM | 5.0 | Apr 29, 2006 |
| CVE-2006-1747 | PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter… | HIGH | 7.5 | Apr 12, 2006 |
| CVE-2006-1636 | PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the… | HIGH | 7.5 | Apr 6, 2006 |
| CVE-2006-1503 | PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attackers to include and ex… | MEDIUM | 5.1 | Mar 30, 2006 |
| CVE-2005-4748 | PHP remote file include vulnerability in functions_admin.php in Virtual War (VWar) 1.5.0 R10 allows remote attackers to include and execute arbitrary PHP code… | MEDIUM | 6.8 | Mar 30, 2006 |
Showing 1 to 22 of 22 CVEs