Skip to main content

Vendor/product archive

phpinv / phpinv CVEs

Beta · best-effort

2 CVEs tagged to phpinv / phpinv0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2008-2694

Published Jun 13, 2008

Cross-site scripting (XSS) vulnerability in search.php in phpInv 0.8.0 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2695

Published Jun 13, 2008

Directory traversal vulnerability in entry.php in phpInv 0.8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1