Vulnerabilities > Phpfaber

DATE CVE VULNERABILITY TITLE RISK
2009-12-22 CVE-2009-4382 Cross-Site Scripting vulnerability in PHPfaber Content Management System 1.3.36
Cross-site scripting (XSS) vulnerability in module.php in PHPFABER CMS, possibly 1.3.36, allows remote attackers to inject arbitrary web script or HTML via the mod parameter.
network
phpfaber CWE-79
4.3
2007-10-31 CVE-2007-5754 Code Injection vulnerability in PHPfaber Urlinn 2.0.5
PHP remote file inclusion vulnerability in urlinn_includes/config.php in phpFaber URLInn 2.0.5 allows remote attackers to execute arbitrary PHP code via a URL in the dir_ws parameter.
network
phpfaber CWE-94
6.8
2007-04-19 CVE-2007-2155 Directory Traversal vulnerability in PHPFaber TopSites Admin/
Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a ..
network
low complexity
phpfaber
7.8
2006-10-31 CVE-2006-5626 Cross-Site Scripting vulnerability in phpFaber CMS
Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the query string, as demonstrated with a vigilon parameter.
network
phpfaber
4.3
2006-07-27 CVE-2006-3902 Cross-Site Scripting vulnerability in PHPfaber Topsites 2.0.9
Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites 2.0.9 allows remote attackers to inject arbitrary web script or HTML via the i_cat parameter.
network
phpfaber
4.3
2006-07-24 CVE-2006-3770 SQL Injection vulnerability in PHPFaber TopSites
Multiple SQL injection vulnerabilities in index.php in phpFaber TopSites 2.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) i_cat or (2) method parameters.
network
low complexity
phpfaber
7.5
2006-04-20 CVE-2006-1878 Cross-Site Scripting vulnerability in PHPfaber Topsites 3
Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites allows remote attackers to inject arbitrary web script or HTML via the page parameter.
network
high complexity
phpfaber
2.6