Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2015-2926

Disclosure Date: April 14, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Php/stats/statsRecent.inc.php in phpTrafficA 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTTP User-Agent header to index.php.
0
Attacker Value
Unknown

CVE-2014-8340

Disclosure Date: December 16, 2014 (last updated October 05, 2023)
SQL injection vulnerability in Php/Functions/log_function.php in phpTrafficA 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via a User-Agent HTTP header.
0
Attacker Value
Unknown

CVE-2008-3566

Disclosure Date: August 10, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter to (1) the default URI or (2) index.php, or (3) the PATH_INFO to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-3647

Disclosure Date: July 10, 2007 (last updated October 04, 2023)
The isloggedin function in Php/login.inc.php in phpTrafficA 1.4.3 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the username cookie to "traffic." NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2007-3426

Disclosure Date: June 27, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
0
Attacker Value
Unknown

CVE-2007-3425

Disclosure Date: June 27, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbitrary local files via the lang parameter, a different vector and version than CVE-2007-1076.2.
0
Attacker Value
Unknown

CVE-2007-3428

Disclosure Date: June 27, 2007 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in phpTrafficA before 1.4.2 allow remote attackers to have an unknown impact via the file parameter to (1) plotStatBar.php or (2) plotStatPie.php, different vectors than CVE-2007-1076.
0
Attacker Value
Unknown

CVE-2006-7209

Disclosure Date: June 27, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in phpTrafficA before 1.2beta2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to keywords results in the (1) main, (2) daily, (3) weekly, (4) monthly, (5) new trends, (6) individual page, and (7) search engine statistics.
0
Attacker Value
Unknown

CVE-2007-3427

Disclosure Date: June 27, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a stats action.
0
Attacker Value
Unknown

CVE-2007-0487

Disclosure Date: January 25, 2007 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in index.php in FreeForum 0.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. NOTE: this issue has been disputed by third party researchers, stating that fpath variable is initialized before being used
0