Skip to main content

Vendor archive

php_heaven CVEs

Beta · best-effort

5 CVEs tagged to vendor php_heaven0 Critical, 2 High, 2 Medium, 1 Low, 0 Unrated.

CVE-2007-6297

Published Dec 10, 2007

Multiple cross-site scripting (XSS) vulnerabilities in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML via the (1) LIMIT parameter to chat/deluser.p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2715

Published Dec 31, 2004

edituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by setting the do_not_login parameter to false.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2716

Published Dec 31, 2004

Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQL commands via the (1) sortBy, (2) sortOrder, (3) startReg,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2717

Published Dec 31, 2004

Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-2718

Published Dec 31, 2004

PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1