Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Virtual War HIGH 7.5
CVE-2010-5063

SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the ratea…

No fix yet
Fix from $1,950 2012-10-08
Virtual War MEDIUM 6.8
CVE-2010-5067

Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for remote attackers to bypa…

No fix yet
Fix from $1,600 2012-10-08
Virtual War MEDIUM 5.0
CVE-2010-5065

popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news posts via a modified newsid…

No fix yet
Fix from $1,600 2012-10-08
Virtual War MEDIUM 5.0
CVE-2010-5279

article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to cause a denial of service (memory consumption) via a large integer in the r…

No fix yet
Fix from $1,600 2012-10-08
Virtual War MEDIUM 5.0
CVE-2011-3813

Virtual War (aka VWar) 1.5.0r15 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the instal…

Mitigation only
Fix from $1,600 2011-09-24
Virtual War HIGH 7.5
CVE-2008-0753

SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month paramet…

No fix yet
Fix from $1,950 2008-02-13
Virtual War HIGH 7.5
CVE-2007-4605

PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute arbitrary …

Fix: after 1.5.0_r15
Fix from $1,950 2007-08-31
Virtual War HIGH 7.5
CVE-2007-2312

Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary SQL comman…

No fix yet
Fix from $1,950 2007-04-26
Virtual War HIGH 7.5
CVE-2006-4141

SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1)…

Fix: after 1.5.0
Fix from $1,950 2006-08-14
Virtual War HIGH 7.5
CVE-2006-4142

SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQL commands…

No fix yet
Fix from $1,950 2006-08-14
Virtual War HIGH 7.5
CVE-2006-4010

SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page…

No fix yet
Fix from $1,950 2006-08-07
Virtual War HIGH 7.5
CVE-2006-3139

Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQL command…

Fix: after 1.5.0_r14
Fix from $1,950 2006-06-22
Virtual War MEDIUM 5.0
CVE-2006-2091

admin.php in Virtual War (VWar) 1.5 and versions before 1.2 allows remote attackers to obtain sensitive information via an invalid vwar_root paramete…

Mitigation only
Fix from $1,600 2006-04-29
Virtual War HIGH 7.5
CVE-2006-1747

PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root …

No fix yet
Fix from $1,950 2006-04-12
Virtual War HIGH 7.5
CVE-2006-1636

PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute arbitrary PHP code via a U…

Patch available
Fix from $1,950 2006-04-06
Virtual War MEDIUM 5.1
CVE-2006-1503

PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attackers to incl…

No fix yet
Fix from $1,600 2006-03-30
Virtual War MEDIUM 6.8
CVE-2005-4748

PHP remote file include vulnerability in functions_admin.php in Virtual War (VWar) 1.5.0 R10 allows remote attackers to include and execute arbitrary…

Patch available
Fix from $1,600 2005-12-31