Pwsphp is a narrowly scoped PHP-based application with a presence in the landscape despite a limited product footprint. The vendor's disclosed vulnerabilities frequently acquire public exploit code, reflecting the accessibility and scriptability characteristic of web-application flaws. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pwsphp over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0943HIGH SQL injection vulnerability in the sondages module in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | Mar 1, 2006 | 7.5 | 34 | NO | YES |
CVE-2006-0942HIGH SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the aff_news_form parameter, | Mar 1, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-0668HIGH SQL injection vulnerability in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in message.php in the espace_membr | Feb 13, 2006 | 7.5 | 28 | NO | YES |
CVE-2005-1509HIGH SQL injection vulnerability in profil.php in PwsPHP 1.2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | May 11, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-1510HIGH PwsPHP 1.2.2 allows remote attackers to obtain sensitive information via a direct request to the admin directory, which reveals the path in an error message. | May 11, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-1511HIGH PwsPHP 1.2.2 allows remote attackers to bypass authentication and post arbitrary comments via the Pseudo cookie. | May 11, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-1512HIGH The Admin panel in PwsPHP 1.2.2 does not properly verify uploaded picture files, which allows remote attackers to upload and possibly execute arbitrary files. | May 11, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-1508MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in PwsPHP 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) month or (2) annee parameters to the n | May 11, 2005 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pwsphp.
Media articles that mention a CVE ID that affects a product developed by Pwsphp — matched by CVE ID, not by vendor name.