Phpcas

Vendor:

First CVE: Oct 7, 2010 · Active for 15 years

9
Total CVEs
More Total CVEs than 86% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Phpcas over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2010
15 years ago
Most Recent CVE
Nov 1, 2022
1,361 days ago

CVE Severity & Scoring

Phpcas9 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (11.1%)
Network4 (44.4%)
Unknown4 (44.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (44.4%)
High1 (11.1%)
Unknown4 (44.4%)
User Interaction
None4 (44.4%)
Unknown4 (44.4%)
Required1 (11.1%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None3 (33.3%)
Unknown4 (44.4%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2
Jan 24, 20209.833NONO
phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP header
Nov 1, 20228.027NONO
Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.
Jul 17, 20178.124NONO
Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create or overwrite arbitrar
Oct 7, 20106.422NONO
A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.
Dec 5, 20195.321NONO
An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the
Dec 5, 20195.520NONO
phpCAS before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows
Jun 6, 20145.820NONO
Multiple cross-site scripting (XSS) vulnerabilities in phpCAS before 1.1.3, when proxy mode is enabled, allow remote attackers to inject arbitrary web script or HTML via (1) a craf
Oct 7, 20104.318NONO
PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to overwrite arbitrary files via a symlink attack on an unspecified file.
Oct 7, 20103.315NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Phpcas

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.3.418.13.6%00
1.3.015.80.6%00
1.2.225.41.1%00
1.1.134.72.2%00
1.1.034.72.2%00
1.0.134.72.2%00
1.0.034.72.2%00
0.6.034.72.2%00
0.5.134.72.2%00
0.5.034.72.2%00
0.4.934.72.2%00
0.4.834.72.2%00
0.4.2334.72.2%00
0.4.2234.72.2%00
0.4.2134.72.2%00
0.4.2034.72.2%00
0.4.1934.72.2%00
0.4.1834.72.2%00
0.4.1734.72.2%00
0.4.1634.72.2%00