Vulnerability index

Browse CVEs

7 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Frontaccounting CRITICAL 9.8
CVE-2019-5720

includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field that can allow the attacker …

No fix yet
Fix from $2,300 2019-01-08
Frontaccounting HIGH 7.5
CVE-2018-1000890

FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the at…

No fix yet
Fix from $1,950 2018-12-28
Frontaccounting HIGH 8.8
CVE-2018-7176

FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Perm…

No fix yet
Fix from $1,950 2018-02-16
Frontaccounting MEDIUM 5.0
CVE-2011-3740

FrontAccounting 2.3.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pat…

No fix yet
Fix from $1,600 2011-09-23
Frontaccounting MEDIUM 6.8
CVE-2007-5148

Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.12 allow remote attackers to execute arbitrary PHP code via a URL in the…

Mitigation only
Fix from $1,600 2007-10-01
Frontaccounting HIGH 9.3
CVE-2007-5117

Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.13, when register_globals is enabled, allow remote attackers to execute …

No fix yet
Fix from $1,950 2007-09-27
Frontaccounting HIGH 7.5
CVE-2007-4279EPSS 75%

PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execute arbitrary PHP code via a UR…

No fix yet
Fix from $1,950 2007-08-09