Skip to main content

Vendor/product archive

travianz_project / travianz CVEs

Beta · best-effort

4 CVEs tagged to travianz_project / travianz2 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2023-36994

Published Jul 7, 2023

In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject PHP code.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-36993

Published Jul 7, 2023

The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.paramet…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-36992

Published Jul 7, 2023

PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36995

Published Jul 6, 2023

TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, or the COOKUSR cookie.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1