Skip to main content

Vendor/product archive

gouguoyin / phprap CVEs

Beta · best-effort

2 CVEs tagged to gouguoyin / phprap2 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2018-11032

Published May 14, 2018

PHPRAP 1.0.4 through 1.0.8 has SQL Injection via the application/home/controller/project.php search() function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-11031

Published May 14, 2018

application/home/controller/debug.php in PHPRAP 1.0.4 through 1.0.8 has SSRF via the /debug URI, as demonstrated by an api[url]=file:////etc/passwd&api[method]=get POST request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1