Coinsoft Technologies
Coinsoft Technologies Phpcoin: vulnerabilidades y CVE
Coinsoft Technologies Phpcoin tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2006-4424 | Media (5.1) | 7.6% | — | 29 ago 2006 | PHP remote file inclusion vulnerability in coin_includes/constants.php in phpCOIN 1.2.3 allows remote attackers to execute arbitrary PHP code via the _CCFG[_PKG_PATH_INCL] parameter. |
| CVE-2006-4425 | Media (5.1) | 4.3% | — | 29 ago 2006 | Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 allow remote attackers to execute arbitrary PHP code via the _CCFG[_PKG_PATH_INCL] parameter in coin_includes scripts including (1) api.php, (2)… |
| CVE-2006-2422 | Media (5) | 1.4% | — | 17 may 2006 | phpCOIN 1.2.3 and earlier stores messages based upon e-mail addresses, which allows remote authenticated users to read messages for other users by adding the sender's e-mail address as an "additional contact". |
| CVE-2006-1428 | Media (4.3) | 2.0% | — | 28 mar 2006 | Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php. |
| CVE-2005-4211 | Alta (7.5) | 9.1% | — | 14 dic 2005 | PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the $_CCFG[_PKG_PATH_DBSE] variable. |
| CVE-2005-4212 | Media (5) | 8.3% | — | 14 dic 2005 | Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) sequences in the $_CCFG[_PKG_PATH_DBSE] variable. |
| CVE-2005-4213 | Alta (7.5) | 3.8% | — | 14 dic 2005 | SQL injection vulnerability in mod.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary SQL commands via the phpcoinsessid cookie. |
| CVE-2005-4214 | Media (5) | 1.8% | — | 14 dic 2005 | phpCOIN 1.2.2 allows remote attackers to obtain the installation path via a direct request to config.php, which leaks the path in an error message because the _CCFG['_PKG_PATH_DBSE'] variable is not defined. |
| CVE-2005-1384 | Alta (7.5) | 2.7% | — | 3 may 2005 | Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index.php, (2) phpcoinsessid parameter to login.php, (3) id, (4)… |
| CVE-2005-0933 | Media (5) | 1.5% | — | 2 may 2005 | Directory traversal vulnerability in auxpage.php for phpCOIN 1.2.1b and earlier allows remote attackers to read arbitrary files via the page parameter. |
| CVE-2005-0669 | Alta (7.5) | 1.6% | — | 2 may 2005 | Multiple SQL injection vulnerabilities in mod.php for phpCOIN 1.2.0 through 1.2.1b allow remote attackers to execute arbitrary SQL commands via the (1) the faq_id in the faq mod, (2) the id parameter in the pages mod,… |
| CVE-2005-0932 | Alta (7.5) | 1.2% | — | 2 may 2005 | Multiple SQL injection vulnerabilities in phpCOIN 1.2.1b and earlier allow remote attackers to execute arbitrary SQL commands (1) via the search engine, (2) the username or email fields in the "forgotten password"… |
| CVE-2005-0670 | Media (4.3) | 4.4% | — | 2 may 2005 | Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web script or HTML via (1) the new parameter to mod.php, (2) the w parameter to mod.php, (3) the e… |
| CVE-2005-0947 | Alta (7.5) | 1.7% | — | 2 may 2005 | Directory traversal vulnerability in auxpage.php in phpCoin 1.2.1b and earlier allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the page parameter. |
| CVE-2005-0946 | Alta (7.5) | 1.2% | — | 29 mar 2005 | SQL injection vulnerability in phpCoin 1.2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the (1) term/keywords field on the search page, (2) username or (3) e-mail field on the forgot… |