Lucene search

K

Phpmyfaq Security Vulnerabilities

cve
cve

CVE-2004-2255

Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename.

6.9AI Score

0.027EPSS

2005-07-17 04:00 AM
31
cve
cve

CVE-2004-2257

phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.

6.7AI Score

0.034EPSS

2005-07-17 04:00 AM
35
cve
cve

CVE-2005-0702

SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.

7.7AI Score

0.002EPSS

2005-03-09 05:00 AM
27
cve
cve

CVE-2005-3046

SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.

7.7AI Score

0.001EPSS

2005-09-24 12:03 AM
30
cve
cve

CVE-2005-3047

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php.

5.7AI Score

0.002EPSS

2005-09-24 12:03 AM
28
cve
cve

CVE-2005-3048

Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a .. (dot dot) in the LANGCODE parameter, which also allows direct code injection via the User Agent field in a request packet, which can be activated ...

7.1AI Score

0.012EPSS

2005-09-24 12:03 AM
25
cve
cve

CVE-2005-3049

PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file.

6.1AI Score

0.007EPSS

2005-09-24 12:03 AM
27
cve
cve

CVE-2005-3050

PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message.

6AI Score

0.005EPSS

2005-09-24 12:03 AM
24
cve
cve

CVE-2005-3734

Cross-site scripting (XSS) vulnerability in the "add content" page in phpMyFAQ 1.5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) thema, (2) username, and (3) usermail parameters.

6AI Score

0.009EPSS

2005-11-22 12:03 AM
28
cve
cve

CVE-2006-6912

SQL injection vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly the userfile or filename parameter.

8.5AI Score

0.009EPSS

2007-01-09 06:00 PM
31
cve
cve

CVE-2006-6913

Unspecified vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to upload arbitrary PHP scripts via unspecified vectors.

7AI Score

0.012EPSS

2007-01-09 06:00 PM
75
cve
cve

CVE-2007-1032

Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploading files on the server."

6.7AI Score

0.007EPSS

2007-02-21 11:28 AM
38
cve
cve

CVE-2009-4040

Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page.

5.7AI Score

0.002EPSS

2009-11-20 07:30 PM
31
cve
cve

CVE-2009-4780

Multiple cross-site scripting (XSS) vulnerabilities in index.php in phpMyFAQ before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter in a sitemap action, (2) the search parameter in a search action, (3) the tagging_id parameter in a search action, (4) t...

5.7AI Score

0.002EPSS

2010-04-21 02:30 PM
43
cve
cve

CVE-2010-4558

phpMyFAQ 2.6.11 and 2.6.12, as distributed between December 4th and December 15th 2010, contains an externally introduced modification (Trojan Horse) in the getTopTen method in inc/Faq.php, which allows remote attackers to execute arbitrary PHP code.

7.7AI Score

0.007EPSS

2010-12-17 07:00 PM
26
cve
cve

CVE-2010-4821

Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

5.9AI Score

0.039EPSS

2012-10-22 11:55 PM
23
cve
cve

CVE-2011-3783

phpMyFAQ 2.6.13 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lang/language_uk.php and certain other files.

6.3AI Score

0.003EPSS

2011-09-24 12:55 AM
26
cve
cve

CVE-2011-4825

Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted param...

7.3AI Score

0.921EPSS

2011-12-15 03:57 AM
48
cve
cve

CVE-2014-0813

Cross-site request forgery (CSRF) vulnerability in phpMyFAQ before 2.8.6 allows remote attackers to hijack the authentication of arbitrary users for requests that modify settings.

7.3AI Score

0.003EPSS

2014-02-14 04:55 PM
25
cve
cve

CVE-2014-0814

Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.8.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.7AI Score

0.003EPSS

2014-02-14 04:55 PM
22
cve
cve

CVE-2014-6045

SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via vectors involving the restore function.

7.2CVSS

7.1AI Score

0.001EPSS

2018-08-28 05:29 PM
24
cve
cve

CVE-2014-6046

Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack the authentication of unspecified users for requests that (1) delete active users by leveraging improper validation of CSRF tokens or that (2) delete open questions, (3) activate us...

8.8CVSS

9.1AI Score

0.001EPSS

2018-08-28 05:29 PM
23
cve
cve

CVE-2014-6047

phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.

5.3CVSS

5AI Score

0.002EPSS

2018-08-28 05:29 PM
25
cve
cve

CVE-2014-6048

phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.

5.3CVSS

5.2AI Score

0.002EPSS

2018-08-28 05:29 PM
24
cve
cve

CVE-2014-6049

phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted instance ID parameter.

2.7CVSS

3.8AI Score

0.001EPSS

2018-08-28 05:29 PM
22
cve
cve

CVE-2014-6050

phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.

5.3CVSS

5.3AI Score

0.001EPSS

2018-08-28 05:29 PM
23
cve
cve

CVE-2017-11187

phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.

9.8CVSS

9.4AI Score

0.002EPSS

2017-07-12 02:29 PM
28
cve
cve

CVE-2017-14618

Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an "Add New FAQ" action.

4.8CVSS

5AI Score

0.007EPSS

2017-09-20 09:29 PM
52
cve
cve

CVE-2017-14619

Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the "Title of your FAQ" field in the Configuration Module.

6.1CVSS

6AI Score

0.006EPSS

2017-09-20 09:29 PM
52
cve
cve

CVE-2017-15727

In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.

5.4CVSS

5.5AI Score

0.001EPSS

2017-10-22 06:29 PM
28
cve
cve

CVE-2017-15728

In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via metaDescription or metaKeywords.

4.8CVSS

5.2AI Score

0.001EPSS

2017-10-22 06:29 PM
27
cve
cve

CVE-2017-15729

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary.

8.8CVSS

8.8AI Score

0.001EPSS

2017-10-22 06:29 PM
28
cve
cve

CVE-2017-15730

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.

8.8CVSS

8.8AI Score

0.002EPSS

2017-10-22 06:29 PM
33
cve
cve

CVE-2017-15731

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.

8.8CVSS

8.8AI Score

0.001EPSS

2017-10-22 06:29 PM
29
cve
cve

CVE-2017-15732

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php.

8.8CVSS

8.8AI Score

0.001EPSS

2017-10-22 06:29 PM
31
cve
cve

CVE-2017-15733

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php.

8.8CVSS

8.8AI Score

0.001EPSS

2017-10-22 06:29 PM
29
cve
cve

CVE-2017-15734

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.

8.8CVSS

8.8AI Score

0.001EPSS

2017-10-22 06:29 PM
27
cve
cve

CVE-2017-15735

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.

8.8CVSS

8.8AI Score

0.001EPSS

2017-10-22 06:29 PM
29
cve
cve

CVE-2017-15808

In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.

8.8CVSS

8.7AI Score

0.001EPSS

2017-10-23 05:29 PM
35
cve
cve

CVE-2017-15809

In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a crafted tag.

6.1CVSS

6.1AI Score

0.001EPSS

2017-10-23 05:29 PM
33
cve
cve

CVE-2017-7579

inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field.

6.1CVSS

5.9AI Score

0.001EPSS

2017-04-07 04:59 PM
29
4
cve
cve

CVE-2018-16650

phpMyFAQ before 2.9.11 allows CSRF.

8.8CVSS

8.6AI Score

0.001EPSS

2018-09-07 05:29 AM
29
cve
cve

CVE-2018-16651

The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.

7.2CVSS

7.3AI Score

0.001EPSS

2018-09-07 05:29 AM
25
cve
cve

CVE-2022-3608

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-alpha.

8.4CVSS

7.8AI Score

0.001EPSS

2022-10-19 01:15 PM
40
7
cve
cve

CVE-2022-3754

Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

9.8CVSS

9.4AI Score

0.002EPSS

2022-10-29 01:15 PM
81
12
cve
cve

CVE-2022-3765

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

5.4CVSS

5.4AI Score

0.001EPSS

2022-10-31 11:15 AM
46
2
cve
cve

CVE-2022-3766

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

6.1CVSS

6.1AI Score

0.001EPSS

2022-10-31 11:15 AM
46
2
cve
cve

CVE-2022-4407

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

6.1CVSS

6.1AI Score

0.001EPSS

2022-12-11 03:15 PM
45
cve
cve

CVE-2022-4408

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

5.4CVSS

5.4AI Score

0.001EPSS

2022-12-11 03:15 PM
58
cve
cve

CVE-2022-4409

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

7.5CVSS

7.4AI Score

0.001EPSS

2022-12-11 03:15 PM
57
Total number of security vulnerabilities116