Phparena maintains a narrowly scoped web-based news application, Panews, where reported vulnerabilities center on cross-site scripting issues arising from improper input neutralization in page generation. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phparena over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2000HIGH Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in | Jun 15, 2005 | 7.5 | 35 | NO | YES |
CVE-2005-2012HIGH Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) i | Jun 20, 2005 | 7.5 | 33 | NO | YES |
CVE-2005-2011MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Que | Jun 20, 2005 | 4.3 | 31 | NO | YES |
CVE-2006-5079HIGH PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pat | Sep 29, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-2361HIGH PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary | May 15, 2006 | 7.5 | 29 | NO | YES |
CVE-2007-4183HIGH SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. | Aug 8, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-3808HIGH SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categories[] parameter in a search action to in | Jul 17, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-4329HIGH SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) newsid and | Dec 17, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-0781HIGH SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to | May 2, 2005 | 7.5 | 28 | NO | YES |
CVE-2006-2209MEDIUM Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the transtype parameter in an add | May 5, 2006 | 6.4 | 25 | NO | YES |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phparena.
Media articles that mention a CVE ID that affects a product developed by Phparena — matched by CVE ID, not by vendor name.