Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown

CVE-2010-0953

Disclosure Date: March 10, 2010 (last updated October 04, 2023)
Directory traversal vulnerability in mod.php in phpCOIN 1.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter.
0
Attacker Value
Unknown

CVE-2007-0861

Disclosure Date: February 09, 2007 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in modules/mail/index.php in phpCOIN RC-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CCFG['_PKG_PATH_MDLS'] parameter. NOTE: this issue has been disputed by a reliable third party, who states that a fatal error occurs before the relevant code is reached
0
Attacker Value
Unknown

CVE-2006-4425

Disclosure Date: August 29, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 allow remote attackers to execute arbitrary PHP code via the _CCFG[_PKG_PATH_INCL] parameter in coin_includes scripts including (1) api.php, (2) common.php, (3) core.php, (4) custom.php, (5) db.php, (6) redirect.php or (7) session_set.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-4424

Disclosure Date: August 29, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in coin_includes/constants.php in phpCOIN 1.2.3 allows remote attackers to execute arbitrary PHP code via the _CCFG[_PKG_PATH_INCL] parameter.
0
Attacker Value
Unknown

CVE-2006-2422

Disclosure Date: May 17, 2006 (last updated October 04, 2023)
phpCOIN 1.2.3 and earlier stores messages based upon e-mail addresses, which allows remote authenticated users to read messages for other users by adding the sender's e-mail address as an "additional contact".
0
Attacker Value
Unknown

CVE-2006-1428

Disclosure Date: March 28, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php.
0
Attacker Value
Unknown

CVE-2005-4211

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the $_CCFG[_PKG_PATH_DBSE] variable.
0
Attacker Value
Unknown

CVE-2005-4213

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
SQL injection vulnerability in mod.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary SQL commands via the phpcoinsessid cookie.
0
Attacker Value
Unknown

CVE-2005-4212

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) sequences in the $_CCFG[_PKG_PATH_DBSE] variable.
0
Attacker Value
Unknown

CVE-2005-4214

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
phpCOIN 1.2.2 allows remote attackers to obtain the installation path via a direct request to config.php, which leaks the path in an error message because the _CCFG['_PKG_PATH_DBSE'] variable is not defined.
0