Show filters
4,018 Total Results
Displaying 241-250 of 4,018
Sort by:
Attacker Value
Unknown

CVE-2023-2752

Disclosure Date: May 17, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.
Attacker Value
Unknown

CVE-2022-47129

Disclosure Date: May 11, 2023 (last updated February 24, 2025)
PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.
Attacker Value
Unknown

CVE-2021-34076

Disclosure Date: May 11, 2023 (last updated February 24, 2025)
File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload.
Attacker Value
Unknown

CVE-2016-15031

Disclosure Date: May 06, 2023 (last updated February 24, 2025)
A vulnerability was found in PHP-Login 1.0. It has been declared as critical. This vulnerability affects the function checkLogin of the file login/scripts/class.loginscript.php of the component POST Parameter Handler. The manipulation of the argument myusername leads to sql injection. The attack can be initiated remotely. Upgrading to version 2.0 is able to address this issue. The patch is identified as 0083ec652786ddbb81335ea20da590df40035679. It is recommended to upgrade the affected component. VDB-228022 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-2550

Disclosure Date: May 05, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.13.
Attacker Value
Unknown

CVE-2023-2427

Disclosure Date: May 05, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.13.
Attacker Value
Unknown

CVE-2023-30268

Disclosure Date: May 04, 2023 (last updated February 24, 2025)
CLTPHP <=6.0 is vulnerable to Improper Input Validation.
Attacker Value
Unknown

CVE-2023-30264

Disclosure Date: May 04, 2023 (last updated February 24, 2025)
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update.
Attacker Value
Unknown

CVE-2023-30205

Disclosure Date: May 03, 2023 (last updated February 24, 2025)
A stored cross-site scripting (XSS) vulnerability in DouPHP v1.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the unique_id parameter in /admin/article.php.
Attacker Value
Unknown

CVE-2023-2429

Disclosure Date: April 30, 2023 (last updated February 24, 2025)
Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.