Vulnerabilities > Phprofession > Phprofession

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-1955 Multiple vulnerability in PHProfession 2.5
SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter.
network
low complexity
phprofession
7.5
2004-12-31 CVE-2004-1953 Multiple vulnerability in PHProfession 2.5
phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message.
network
low complexity
phprofession
5.0
2004-04-21 CVE-2004-1954 Multiple vulnerability in PHProfession 2.5
Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.
network
phprofession
4.3