Skip to main content

Vendor/product archive

php_arena / pafaq CVEs

Beta · best-effort

5 CVEs tagged to php_arena / pafaq0 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2005-2011

Published Jun 20, 2005

Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Qu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2012

Published Jun 20, 2005

Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2013

Published Jun 20, 2005

paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, which contains a backup of the database including usernames and…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2014

Published Jun 20, 2005

The "upload a language pack" feature in paFAQ 1.0 Beta 4 allows remote authenticated administrators to execute arbitrary PHP commands by uploading a malicious language pack.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0475

Published Mar 30, 2005

SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (3) order, or (4) ord…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1