Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2006-2422

Disclosure Date: May 17, 2006 (last updated October 04, 2023)
phpCOIN 1.2.3 and earlier stores messages based upon e-mail addresses, which allows remote authenticated users to read messages for other users by adding the sender's e-mail address as an "additional contact".
0
Attacker Value
Unknown

CVE-2006-1428

Disclosure Date: March 28, 2006 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php.
0
Attacker Value
Unknown

CVE-2005-4211

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the $_CCFG[_PKG_PATH_DBSE] variable.
0
Attacker Value
Unknown

CVE-2005-4213

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
SQL injection vulnerability in mod.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary SQL commands via the phpcoinsessid cookie.
0
Attacker Value
Unknown

CVE-2005-4212

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) sequences in the $_CCFG[_PKG_PATH_DBSE] variable.
0
Attacker Value
Unknown

CVE-2005-4214

Disclosure Date: December 14, 2005 (last updated February 22, 2025)
phpCOIN 1.2.2 allows remote attackers to obtain the installation path via a direct request to config.php, which leaks the path in an error message because the _CCFG['_PKG_PATH_DBSE'] variable is not defined.
0