Phpdevshell is a web application framework with a narrow product scope, and its observed vulnerabilities center on information-disclosure and access-control weaknesses characteristic of server-side application frameworks. The durable signal is the concentration of exposures in the core framework product around sensitive data handling and authorization boundaries; live severity, exploitation, and coverage counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpdevshell over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6186HIGH Unspecified vulnerability in PHPDevShell before 0.7.0 has unknown impact and attack vectors, involving a "minor security bug in repair & optimize database." | Nov 30, 2007 | 10.0 | 24 | NO | NO |
CVE-2007-6174HIGH PHPDevShell before 0.7.0 allows remote authenticated users to gain privileges via a crafted request to update a user profile. NOTE: some of these details are obtained from third p | Nov 30, 2007 | 8.5 | 21 | NO | NO |
CVE-2011-3773MEDIUM PHPDevShell 3.0.0-Beta-4b allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as d | Sep 24, 2011 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpdevshell.
Media articles that mention a CVE ID that affects a product developed by Phpdevshell — matched by CVE ID, not by vendor name.