Phpcas
Vendor:
First CVE: Oct 7, 2010 · Active for 15 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Phpcas over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2010
15 years ago
Most Recent CVE
Nov 1, 2022
1,361 days ago
CVE Severity & Scoring
Phpcas9 CVEs
11%
56%
22%
11%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (11.1%)
Network4 (44.4%)
Unknown4 (44.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (44.4%)
High1 (11.1%)
Unknown4 (44.4%)
User Interaction
None4 (44.4%)
Unknown4 (44.4%)
Required1 (11.1%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None3 (33.3%)
Unknown4 (44.4%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-4172CRITICAL A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2 | Jan 24, 2020 | 9.8 | 33 | NO | NO |
CVE-2022-39369HIGH phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP header | Nov 1, 2022 | 8.0 | 27 | NO | NO |
CVE-2017-1000071HIGH Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server. | Jul 17, 2017 | 8.1 | 24 | NO | NO |
CVE-2010-3692MEDIUM Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create or overwrite arbitrar | Oct 7, 2010 | 6.4 | 22 | NO | NO |
CVE-2012-1104MEDIUM A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed. | Dec 5, 2019 | 5.3 | 21 | NO | NO |
CVE-2012-1105MEDIUM An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the | Dec 5, 2019 | 5.5 | 20 | NO | NO |
CVE-2012-5583MEDIUM phpCAS before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows | Jun 6, 2014 | 5.8 | 20 | NO | NO |
CVE-2010-3690MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in phpCAS before 1.1.3, when proxy mode is enabled, allow remote attackers to inject arbitrary web script or HTML via (1) a craf | Oct 7, 2010 | 4.3 | 18 | NO | NO |
PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to overwrite arbitrary files via a symlink attack on an unspecified file. | Oct 7, 2010 | 3.3 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Phpcas
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.3.4 | 1 | 8.1 | 3.6% | 0 | 0 |
| 1.3.0 | 1 | 5.8 | 0.6% | 0 | 0 |
| 1.2.2 | 2 | 5.4 | 1.1% | 0 | 0 |
| 1.1.1 | 3 | 4.7 | 2.2% | 0 | 0 |
| 1.1.0 | 3 | 4.7 | 2.2% | 0 | 0 |
| 1.0.1 | 3 | 4.7 | 2.2% | 0 | 0 |
| 1.0.0 | 3 | 4.7 | 2.2% | 0 | 0 |
| 0.6.0 | 3 | 4.7 | 2.2% | 0 | 0 |
| 0.5.1 | 3 | 4.7 | 2.2% | 0 | 0 |
| 0.5.0 | 3 | 4.7 | 2.2% | 0 | 0 |
| 0.4.9 | 3 | 4.7 | 2.2% | 0 | 0 |
| 0.4.8 | 3 | 4.7 | 2.2% | 0 | 0 |
| 0.4.23 | 3 | 4.7 | 2.2% | 0 | 0 |
| 0.4.22 | 3 | 4.7 | 2.2% | 0 | 0 |
| 0.4.21 | 3 | 4.7 | 2.2% | 0 | 0 |
| 0.4.20 | 3 | 4.7 | 2.2% | 0 | 0 |
| 0.4.19 | 3 | 4.7 | 2.2% | 0 | 0 |
| 0.4.18 | 3 | 4.7 | 2.2% | 0 | 0 |
| 0.4.17 | 3 | 4.7 | 2.2% | 0 | 0 |
| 0.4.16 | 3 | 4.7 | 2.2% | 0 | 0 |