This page lists publicly disclosed CVE vulnerabilities affecting idevspot phphostbot (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2011-3779 | PhpHostBot 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/create_acct.php and certain other files. | [email protected] | 5.0 | 1.23% | 2011-09-24 | 2026-04-29 |
| CVE-2007-4231 | PHP remote file inclusion vulnerability in order/login.php in IDevSpot PhpHostBot 1.06 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the svr_rootscript parameter, a different vector than CVE-2007-4094 and CVE-2006-3776. | [email protected] | 6.8 | 3.58% | 2007-08-08 | 2026-04-23 |
| CVE-2007-4094 | PHP remote file inclusion vulnerability in library/authorize.php in IDevSpot PhpHostBot allows remote attackers to execute arbitrary PHP code via a URL in the login_form parameter, a different vector than CVE-2006-3776. | [email protected] | 7.5 | 1.70% | 2007-07-30 | 2026-04-23 |
| CVE-2006-3776 | PHP remote file inclusion vulnerability in order/index.php in IDevSpot (1) PhpHostBot 1.0 and (2) AutoHost 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | [email protected] | 7.5 | 3.22% | 2006-07-24 | 2026-04-16 |