Phpwebthings

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 9
    Known Exploited: 0
    0
    Critical Level Threats
    5
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2009-2147

    SQL injection vulnerability in fdown.php in phpWebThings 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Last Modified: Apr 23, 2026
    Published: Jun 22, 2009

    CVE-2009-2081

    Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter.

    Last Modified: Apr 23, 2026
    Published: Jun 16, 2009

    CVE-2007-3141

    PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the editor_insert_top parameter. NOTE: the editor_insert_bottom vector is already covered by CVE-2006-6042.

    Last Modified: Apr 23, 2026
    Published: Jun 11, 2007

    CVE-2006-6042

    PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the editor_insert_bottom parameter.

    Last Modified: Apr 23, 2026
    Published: Nov 22, 2006

    CVE-2005-4218

    SQL injection vulnerability in forum.php in PHPWebThings 1.4 allows remote attackers to execute arbitrary SQL commands via the msg parameter, a different vulnerability than CVE-2005-3585.

    Last Modified: Apr 16, 2026
    Published: Dec 14, 2005
    Items Per Page