Vulnerability index

Browse CVEs

117 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Phpmyfaq HIGH 7.2
CVE-2014-6045

SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands vi…

Fix: 2.8.13+
Fix from $1,950 2018-08-28
Phpmyfaq HIGH 8.8
CVE-2017-15808

In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.

Fix: after 2.9.8
Fix from $1,950 2017-10-23
Phpmyfaq MEDIUM 6.1
CVE-2017-15809

In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a crafted tag.

Fix: after 2.9.8
Fix from $1,600 2017-10-23
Phpmyfaq HIGH 8.8
CVE-2017-15729

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary.

Fix: after 2.9.8
Fix from $1,950 2017-10-22
Phpmyfaq HIGH 8.8
CVE-2017-15730

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.

Fix: after 2.9.8
Fix from $1,950 2017-10-22
Phpmyfaq HIGH 8.8
CVE-2017-15731

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.

Fix: after 2.9.8
Fix from $1,950 2017-10-22
Phpmyfaq HIGH 8.8
CVE-2017-15732

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php.

Fix: after 2.9.8
Fix from $1,950 2017-10-22
Phpmyfaq HIGH 8.8
CVE-2017-15733

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php.

Fix: after 2.9.8
Fix from $1,950 2017-10-22
Phpmyfaq HIGH 8.8
CVE-2017-15734

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.

Fix: after 2.9.8
Fix from $1,950 2017-10-22
Phpmyfaq HIGH 8.8
CVE-2017-15735

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.

Fix: after 2.9.8
Fix from $1,950 2017-10-22
Phpmyfaq MEDIUM 5.4
CVE-2017-15727

In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.

Fix: after 2.9.8
Fix from $1,600 2017-10-22
Phpmyfaq MEDIUM 6.1
CVE-2017-14619

Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the "Title of y…

Fix: after 2.9.8
Fix from $1,600 2017-09-20
Phpmyfaq CRITICAL 9.8
CVE-2017-11187

phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.

Fix: after 2.9.7
Fix from $2,300 2017-07-12
Phpmyfaq MEDIUM 6.1
CVE-2017-7579

inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field.

Fix: after 2.9.6
Fix from $1,600 2017-04-07
Phpmyfaq MEDIUM 6.8
CVE-2014-0813

Cross-site request forgery (CSRF) vulnerability in phpMyFAQ before 2.8.6 allows remote attackers to hijack the authentication of arbitrary users for …

Fix: after 2.8.5
Fix from $1,600 2014-02-14
Phpmyfaq MEDIUM 5.0
CVE-2011-3783

phpMyFAQ 2.6.13 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in a…

Mitigation only
Fix from $1,600 2011-09-24
Phpmyfaq HIGH 7.5
CVE-2010-4558

phpMyFAQ 2.6.11 and 2.6.12, as distributed between December 4th and December 15th 2010, contains an externally introduced modification (Trojan Horse)…

Patch available
Fix from $1,950 2010-12-17
Phpmyfaq MEDIUM 6.8
CVE-2007-1032

Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploadi…

Fix: after 1.6.9
Fix from $1,600 2007-02-21
Phpmyfaq HIGH 7.5
CVE-2006-6912

SQL injection vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly…

Fix: after 1.6.7
Fix from $1,950 2006-12-31
Phpmyfaq HIGH 7.5
CVE-2006-6913

Unspecified vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to upload arbitrary PHP scripts via unspecified vectors.

Fix: after 1.6.7
Fix from $1,950 2006-12-31
Phpmyfaq MEDIUM 6.8
CVE-2005-3046

SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the…

No fix yet
Fix from $1,600 2005-09-24
Phpmyfaq MEDIUM 6.4
CVE-2005-3048EPSS 8%

Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a…

Mitigation only
Fix from $1,600 2005-09-24
Phpmyfaq MEDIUM 5.0
CVE-2005-3049

PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attacker…

No fix yet
Fix from $1,600 2005-09-24
Phpmyfaq MEDIUM 5.0
CVE-2005-3050

PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an err…

No fix yet
Fix from $1,600 2005-09-24
Phpmyfaq MEDIUM 5.0
CVE-2005-0702

SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messag…

Patch available
Fix from $1,600 2005-03-07
Phpmyfaq MEDIUM 6.4
CVE-2004-2255

Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the a…

Patch available
Fix from $1,600 2004-12-31
Phpmyfaq MEDIUM 5.3
CVE-2004-2257

phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.

Patch available
Fix from $1,600 2004-12-31