phpkit software vulnerabilities
vulnerabilities.aspcode.net
Searching phpkit software vulnerabilities
Cross-site scripting (XSS) vulnerability in inc
Cross-site
|
scripting
|
Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter.
SQL injection vulnerability in include.php in P
vulnerability
|
includephp
|
injection
|
PHPKIT
|
SQL
|
SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Cross-site scripting (XSS) vulnerability in PHP
Cross-site
|
scripting
|
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum messages.
Multiple SQL injection vulnerabilities in PHPKi
vulnerabilities
|
injection
|
Multiple
|
PHPKit
|
SQL
|
Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to login/member.php or (2) im_receiver parameter to login/imcenter.php.
Unrestricted file upload vulnerability in admin
admin/adminphp
|
vulnerability
|
Unrestricted
|
PHPKit
|
upload
|
file
|
Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a .php file to the content/images/ directory using images.php. NOTE: if a PHPKit administrator must already have access to the end system to install or modify configuration of the product, then this issue might not cross privilege boundaries, and should not be included in CVE.
Multiple cross-site scripting (XSS) vulnerabili
cross-site
|
scripting
|
Multiple
|
Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, and the (5) referer statistics, the (6) HTML title element and (7) logo alt attributes in forum postings, and the (8) Homepage field in the Guestbook.
Multiple SQL injection vulnerabilities in inclu
vulnerabilities
|
includephp
|
injection
|
Multiple
|
PHPKIT
|
SQL
|
Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in conjunction with the login/userinfo.php path and (2) the session parameter (aka the PHPKITSID variable).
Multiple eval injection vulnerabilities in the
vulnerabilities
|
injection
|
function
|
Multiple
|
PHPKIT
|
eval
|
help
|
Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary code on the server via unknown attack vectors involving uninitialized variables.
Directory traversal vulnerability in PHPKIT 1.6
vulnerability
|
traversal
|
Directory
|
PHPKIT
|
Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the path parameter and a %00 at the end of the filename, as demonstrated by an avatar filename ending with .png%00.
Absolute path traversal vulnerability in includ
vulnerability
|
includephp
|
traversal
|
Absolute
|
PHPKIT
|
path
|
Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arbitrary local files via a direct request with a path parameter with a null character and beginning with (1) '/' (slash) for an absolute pathname or (2) a drive letter (such as "C:"), which bypasses checks for ".." sequences and trailing ".php" extensions.
Incomplete blacklist vulnerability in include.p
vulnerability
|
includephp
|
Incomplete
|
blacklist
|
PHPKIT
|
Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackers to conduct PHP remote file include attacks via a path parameter that specifies a (1) UNC share or (2) ftps URL, which bypasses the check for "http://", "ftp://", and "https://" URLs.
Cross-site scripting (XSS) vulnerability in PHP
Cross-site
|
scripting
|
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error parameter to include.php, possibly due to a problem in login/login.php.
SQL injection vulnerability in include.php in P
vulnerability
|
includephp
|
injection
|
PHPKIT
|
SQL
|
SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands via the contentid parameter, possibly involving content/news.php.
SQL injection vulnerability in PHPKit 1.6.1 RC2
vulnerability
|
injection
|
PHPKit
|
SQL
|
SQL injection vulnerability in PHPKit 1.6.1 RC2 allows remote attackers to inject arbitrary SQL commands via the catid parameter to include.php when the path parameter is set to faq/faq.php, and other unspecified vectors involving guestbook/print.php.
SQL injection vulnerability in comment.php in P
vulnerability
|
commentphp
|
injection
|
PHPKIT
|
SQL
|
SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parameter.
Software vulnerabilities results 1 to 16 of 16
Page:
1