PHP Collab is a niche project-management and collaboration platform with a very limited vulnerability footprint. Current vulnerability activity and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Php Collab over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6090HIGH Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with | Oct 3, 2017 | 8.8 | 93 | NO | YES |
CVE-2017-6089CRITICAL SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id parameters to topics/deletetopics.php | Oct 3, 2017 | 9.8 | 43 | NO | YES |
CVE-2006-1495HIGH SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL c | Mar 30, 2006 | 7.5 | 32 | NO | YES |
CVE-2017-15907CRITICAL SQL injection vulnerability in phpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to newsdesk/newsdesk.php. | Oct 26, 2017 | 9.8 | 28 | NO | NO |
CVE-2008-4305HIGH Static code injection vulnerability in installation/setup.php in phpCollab 2.5 rc3 and earlier allows remote authenticated administrators to inject arbitrary PHP code into include/ | Dec 23, 2008 | 9.0 | 25 | NO | NO |
CVE-2008-4304HIGH general/login.php in phpCollab 2.5 rc3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified input related to the SSL_CLIENT_CER | Dec 23, 2008 | 10.0 | 25 | NO | NO |
CVE-2011-3772MEDIUM phpCollab 2.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated | Sep 24, 2011 | 5.0 | 18 | NO | NO |
CVE-2008-4303MEDIUM Multiple SQL injection vulnerabilities in phpCollab 2.5 rc3, 2.4, and earlier allow remote attackers to execute arbitrary SQL commands via the loginForm parameter to general/login. | Dec 23, 2008 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Php Collab.
Media articles that mention a CVE ID that affects a product developed by Php Collab — matched by CVE ID, not by vendor name.