Vulnerabilities > PHP Arena > Medium

DATE CVE VULNERABILITY TITLE RISK
2006-05-05 CVE-2006-2209 SQL Injection vulnerability in PHP Arena Pacheckbook 1.1
Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the transtype parameter in an add action or (2) entry parameter in an edit action.
network
low complexity
php-arena
6.4
2005-06-20 CVE-2005-2014 Local Security vulnerability in PHP Arena Pafaq 1.0Beta4
The "upload a language pack" feature in paFAQ 1.0 Beta 4 allows remote authenticated administrators to execute arbitrary PHP commands by uploading a malicious language pack.
local
low complexity
php-arena
4.6
2005-06-20 CVE-2005-2013 Information Disclosure vulnerability in PHP Arena Pafaq 1.0Beta4
paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, which contains a backup of the database including usernames and passwords.
network
low complexity
php-arena
5.0
2005-06-20 CVE-2005-2011 Cross-Site Scripting vulnerability in PHP Arena Pafaq 1.0Beta4
Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Question action.
network
php-arena
4.3
2005-06-15 CVE-2005-2001 Directory Traversal vulnerability in paFileDB
Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a ..
network
low complexity
php-arena
5.0
2005-06-15 CVE-2005-1999 Cross-Site Scripting vulnerability in PHP Arena Pafiledb 3.1
Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the category action (category.php), or (3) pages parameter in the viewall action (viewall.php).
network
php-arena
4.3
2005-05-02 CVE-2005-0952 Unspecified vulnerability in PHP Arena Pafiledb 3.1
Cross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
network
low complexity
php-arena
5.0
2005-05-02 CVE-2005-0782 SQL Injection And Cross-Site Scripting vulnerability in PAFileDB
Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to pafiledb.php.
network
php-arena
4.3
2005-05-02 CVE-2005-0724 Information Disclosure vulnerability in paFileDB
paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via (1) an invalid str parameter to pafiledb.php, or a direct request to (2) viewall.php, (3) stats.php, (4) search.php, (5) rate.php, (6) main.php, (7) license.php, (8) category.php, (9) download.php, (10) file.php, (11) email.php, or (12) admin.php, which reveals the path in a PHP error message.
network
low complexity
php-arena
5.0
2005-05-02 CVE-2005-0647 Remote Security vulnerability in PHP Arena Panews 2.0.4B
admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters, which are written to config.php.
network
low complexity
php-arena
5.0