Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Phpkit HIGH 8.8
CVE-2016-10758

PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_na…

No fix yet
Fix from $1,950 2019-05-24
Phpkit MEDIUM 6.8
CVE-2008-7193

PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by reading th…

Mitigation only
Fix from $1,600 2009-09-09
Phpkit HIGH 7.5
CVE-2007-6134

SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via the contenti…

Patch available
Fix from $1,950 2007-11-27
Phpkit HIGH 7.5
CVE-2006-7115

SQL injection vulnerability in PHPKit 1.6.1 RC2 allows remote attackers to inject arbitrary SQL commands via the catid parameter to include.php when …

No fix yet
Fix from $1,950 2007-03-06
Phpkit HIGH 7.5
CVE-2007-0179

SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parameter.

No fix yet
Fix from $1,950 2007-01-11
Phpkit MEDIUM 6.4
CVE-2006-1773

SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands via the co…

Fix: after 1.6.1
Fix from $1,600 2006-04-13
Phpkit MEDIUM 6.8
CVE-2006-1507

Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error parameter to i…

No fix yet
Fix from $1,600 2006-03-30
Phpkit MEDIUM 6.4
CVE-2006-0785

Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arbitrary l…

Fix: after 1.6.1
Fix from $1,600 2006-02-19
Phpkit MEDIUM 5.1
CVE-2006-0786

Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackers to con…

Fix: after 1.6.1
Fix from $1,600 2006-02-19
Phpkit MEDIUM 6.5
CVE-2005-4424

Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a .. (dot d…

Mitigation only
Fix from $1,600 2005-12-20
Phpkit HIGH 7.5
CVE-2005-3553

Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL commands via the…

Fix: after 1.6.1
Fix from $1,950 2005-11-16
Phpkit MEDIUM 5.1
CVE-2005-3554

Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote attackers…

No fix yet
Fix from $1,600 2005-11-16
Phpkit HIGH 7.5
CVE-2005-2683

Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to login…

No fix yet
Fix from $1,950 2005-08-23
Phpkit HIGH 7.5
CVE-2004-1538

SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the id parame…

No fix yet
Fix from $1,950 2004-12-31
Phpkit MEDIUM 6.8
CVE-2003-1187

Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML vi…

No fix yet
Fix from $1,600 2003-11-02