Vulnerabilities > Phprpg
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2007-12-20 | CVE-2007-6484 | SQL Injection vulnerability in PHPrpg 0.8 SQL injection vulnerability in index.php in phpRPG 0.8 allows remote attackers to execute arbitrary SQL commands via the password parameter. | 6.8 |
2007-12-20 | CVE-2007-6470 | Permissions, Privileges, and Access Controls vulnerability in PHPrpg 0.8 phpRPG 0.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read session ID values in files under tmp/, and then hijack sessions via PHPSESSID cookies. | 6.4 |
2007-12-20 | CVE-2007-6469 | SQL Injection vulnerability in PHPrpg 0.8 SQL injection vulnerability in index.php in phpRPG 0.8, when magic_qutoes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. | 9.3 |