efiction_project CVE 脆弱性と CVE 一覧(7)

製品(CPE): — CVE 件数: 7

efiction_project 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to efiction_project, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 17 / 7 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2005-4173 eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information by accessing phpinfo.php, which executes the PHP phpinfo function. [email protected] 5.0 1.76% 2005-12-11 2026-04-16
CVE-2005-4172 eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error message. [email protected] 5.0 1.76% 2005-12-11 2026-04-16
CVE-2005-4171 The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a filename with a .php extension that contains a GIF header, which passes the image validity check but executes any PHP code within the file. [email protected] 7.5 7.90% 2005-12-11 2026-04-16
CVE-2005-4170 SQL injection vulnerability in eFiction 1.1 allows remote attackers to execute arbitrary SQL commands via the uid parameter to viewuser.php. [email protected] 7.5 2.05% 2005-12-11 2026-04-16
CVE-2005-4169 Multiple SQL injection vulnerabilities in eFiction 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) let parameter in a viewlist action to authors.php and (2) sid parameter to viewstory.php. [email protected] 7.5 2.18% 2005-12-11 2026-04-16
CVE-2005-4168 Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let parameter in a viewlist action to titles.php and (2) the username. [email protected] 7.5 3.44% 2005-12-11 2026-04-16
CVE-2005-4167 Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the let parameter in a viewlist action to titles.php. [email protected] 4.3 3.60% 2005-12-11 2026-04-16
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence