RSS   Vulnerabilities for 'Phphostbot'   RSS

2011-09-23
 
CVE-2011-3779

 

 
PhpHostBot 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/create_acct.php and certain other files.

 
2007-08-08
 
CVE-2007-4231

 

 
PHP remote file inclusion vulnerability in order/login.php in IDevSpot PhpHostBot 1.06 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the svr_rootscript parameter, a different vector than CVE-2007-4094 and CVE-2006-3776.

 
2007-07-30
 
CVE-2007-4094

 

 
PHP remote file inclusion vulnerability in library/authorize.php in IDevSpot PhpHostBot allows remote attackers to execute arbitrary PHP code via a URL in the login_form parameter, a different vector than CVE-2006-3776.

 
2006-07-24
 
CVE-2006-3776

CWE-94
 

 
PHP remote file inclusion vulnerability in order/index.php in IDevSpot (1) PhpHostBot 1.0 and (2) AutoHost 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

 

 >>> Vendor: Idevspot 9 Products
Isupport
Autohost
Phphostbot
Phplinkexchange
Textads
Bizdirectory
Nixieaffiliate
Idevcart
Idev-businessdirectory


Copyright 2022, cxsecurity.com

 

Back to Top