Bugada Andrea
Bugada Andrea PHP Advanced Transfer Manager: vulnerabilidades y CVE
Bugada Andrea PHP Advanced Transfer Manager tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2007-2659 | Media (5) | 6.8% | — | 14 may 2007 | Directory traversal vulnerability in index.php in PHP Advanced Transfer Manager (phpATM) 1.30 allows remote attackers to read arbitrary files and obtain script source code via a .. (dot dot) in the directory parameter… |
| CVE-2006-4749 | Alta (7.5) | 2.1% | — | 13 sept 2006 | Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpATM) 1.20 allow remote attackers to execute arbitrary PHP code via the include_location parameter in (1) activate.php, (2)… |
| CVE-2006-4594 | Alta (7.5) | 2.5% | — | 6 sept 2006 | Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpAtm) 1.21 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the include_location parameter in (1)… |
| CVE-2006-1209 | Media (5) | 3.4% | — | 14 mar 2006 | PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access control, which allows remote attackers to download each password hash… |
| CVE-2005-2998 | Alta (7.5) | 1.4% | — | 20 sept 2005 | PHP Advanced Transfer Manager 1.30 has a default password for the administrator user, which allows remote attackers to upload and execute arbitrary PHP files. |
| CVE-2005-2999 | Media (5) | 1.2% | — | 20 sept 2005 | PHP Advanced Transfer Manager 1.30 allows remote attackers to obtain sensitive PHP configuration information via a direct request to test.php. |
| CVE-2005-2997 | Media (5) | 1.5% | — | 20 sept 2005 | Multiple directory traversal vulnerabilities in PHP Advanced Transfer Manager 1.30 allow remote attackers to read arbitrary files via ".." sequences in (1) the currentdir parameter to txt.php, or the current_dir… |
| CVE-2005-3000 | Media (4.3) | 0.99% | — | 20 sept 2005 | Multiple cross-site scripting (XSS) vulnerabilities in viewers/txt.php in PHP Advanced Transfer Manager 1.30 allow remote attackers to inject arbitrary web script or HTML via the (1) font, (2) normalfontcolor, or (3)… |
| CVE-2005-1681 | Alta (7.5) | 6.6% | — | 20 may 2005 | PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the include_location parameter to index.php. |
| CVE-2005-1604 | Alta (7.5) | 5.1% | — | 16 may 2005 | PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as demonstrated using a filename ending in "php.ns", which allows… |