Efiction-project
7 CVEs tracked since 2005. Since Dec 2005, none of them reached CISA KEV.
Efiction-project CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2005-12 | 7 | 0 |
Products
The products that kept showing up in Efiction-project's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 7 most recently published vulnerabilities affecting Efiction-project.
- CVE-2005-4167Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the let parameter in a viewlist action to titles.php.4.3
- CVE-2005-4170SQL injection vulnerability in eFiction 1.1 allows remote attackers to execute arbitrary SQL commands via the uid parameter to viewuser.php.7.5
- CVE-2005-4173eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information by accessing phpinfo.php, which executes the PHP phpinfo function.5.0
- CVE-2005-4172eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error...5.0
- CVE-2005-4168Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let parameter in a viewlist action to titles.php and (2) th...7.5
- CVE-2005-4169Multiple SQL injection vulnerabilities in eFiction 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) let parameter in a viewlist action to authors.php and (2) sid parameter t...7.5
- CVE-2005-4171The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a filename with a ....7.5
The record
- Peak rank
- #5 in Dec 2005
- Busiest month shown
- Dec 2005, 7 CVEs
- Months with a KEV entry
- 0 since Dec 2005
- Monthly snapshots
- 1 since 2005