Bugada Andrea
Bugada Andrea PHP Advanced Transfer Manager: vulnerabilities and CVEs
Bugada Andrea PHP Advanced Transfer Manager has 10 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs10
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2007-2659 | Medium (5) | 6.8% | — | May 14, 2007 | Directory traversal vulnerability in index.php in PHP Advanced Transfer Manager (phpATM) 1.30 allows remote attackers to read arbitrary files and obtain script source code via a .. (dot dot) in the directory parameter… |
| CVE-2006-4749 | High (7.5) | 2.1% | — | Sep 13, 2006 | Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpATM) 1.20 allow remote attackers to execute arbitrary PHP code via the include_location parameter in (1) activate.php, (2)… |
| CVE-2006-4594 | High (7.5) | 2.5% | — | Sep 6, 2006 | Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpAtm) 1.21 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the include_location parameter in (1)… |
| CVE-2006-1209 | Medium (5) | 3.4% | — | Mar 14, 2006 | PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access control, which allows remote attackers to download each password hash… |
| CVE-2005-2998 | High (7.5) | 1.4% | — | Sep 20, 2005 | PHP Advanced Transfer Manager 1.30 has a default password for the administrator user, which allows remote attackers to upload and execute arbitrary PHP files. |
| CVE-2005-2999 | Medium (5) | 1.2% | — | Sep 20, 2005 | PHP Advanced Transfer Manager 1.30 allows remote attackers to obtain sensitive PHP configuration information via a direct request to test.php. |
| CVE-2005-2997 | Medium (5) | 1.5% | — | Sep 20, 2005 | Multiple directory traversal vulnerabilities in PHP Advanced Transfer Manager 1.30 allow remote attackers to read arbitrary files via ".." sequences in (1) the currentdir parameter to txt.php, or the current_dir… |
| CVE-2005-3000 | Medium (4.3) | 0.99% | — | Sep 20, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in viewers/txt.php in PHP Advanced Transfer Manager 1.30 allow remote attackers to inject arbitrary web script or HTML via the (1) font, (2) normalfontcolor, or (3)… |
| CVE-2005-1681 | High (7.5) | 6.6% | — | May 20, 2005 | PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the include_location parameter to index.php. |
| CVE-2005-1604 | High (7.5) | 5.1% | — | May 16, 2005 | PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as demonstrated using a filename ending in "php.ns", which allows… |