Vwar
18 CVEs tracked since 2006. Since Mar 2006, none of them reached CISA KEV.
Vwar CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2006-03 | 2 | 0 |
| 2006-04 | 3 | 0 |
| 2006-05 | null or fewer | |
| 2006-06 | null or fewer | |
| 2006-07 | null or fewer | |
| 2006-08 | 5 | 0 |
| 2006-09 | null or fewer | |
| 2006-10 | null or fewer | |
| 2006-11 | null or fewer | |
| 2006-12 | null or fewer | |
| 2007-01 | null or fewer | |
| 2007-02 | null or fewer | |
| 2007-03 | null or fewer | |
| 2007-04 | 2 | 0 |
| 2007-05 | null or fewer | |
| 2007-06 | null or fewer | |
| 2007-07 | null or fewer | |
| 2007-08 | null or fewer | |
| 2007-09 | null or fewer | |
| 2007-10 | null or fewer | |
| 2007-11 | null or fewer | |
| 2007-12 | null or fewer | |
| 2008-01 | null or fewer | |
| 2008-02 | null or fewer | |
| 2008-03 | null or fewer | |
| 2008-04 | null or fewer | |
| 2008-05 | null or fewer | |
| 2008-06 | null or fewer | |
| 2008-07 | null or fewer | |
| 2008-08 | null or fewer | |
| 2008-09 | null or fewer | |
| 2008-10 | null or fewer | |
| 2008-11 | null or fewer | |
| 2008-12 | null or fewer | |
| 2009-01 | null or fewer | |
| 2009-02 | null or fewer | |
| 2009-03 | null or fewer | |
| 2009-04 | null or fewer | |
| 2009-05 | null or fewer | |
| 2009-06 | null or fewer | |
| 2009-07 | null or fewer | |
| 2009-08 | null or fewer | |
| 2009-09 | null or fewer | |
| 2009-10 | null or fewer | |
| 2009-11 | null or fewer | |
| 2009-12 | null or fewer | |
| 2010-01 | null or fewer | |
| 2010-02 | null or fewer | |
| 2010-03 | null or fewer | |
| 2010-04 | null or fewer | |
| 2010-05 | null or fewer | |
| 2010-06 | null or fewer | |
| 2010-07 | null or fewer | |
| 2010-08 | null or fewer | |
| 2010-09 | null or fewer | |
| 2010-10 | null or fewer | |
| 2010-11 | null or fewer | |
| 2010-12 | null or fewer | |
| 2011-01 | null or fewer | |
| 2011-02 | null or fewer | |
| 2011-03 | null or fewer | |
| 2011-04 | null or fewer | |
| 2011-05 | null or fewer | |
| 2011-06 | null or fewer | |
| 2011-07 | null or fewer | |
| 2011-08 | null or fewer | |
| 2011-09 | null or fewer | |
| 2011-10 | null or fewer | |
| 2011-11 | null or fewer | |
| 2011-12 | null or fewer | |
| 2012-01 | null or fewer | |
| 2012-02 | null or fewer | |
| 2012-03 | null or fewer | |
| 2012-04 | null or fewer | |
| 2012-05 | null or fewer | |
| 2012-06 | null or fewer | |
| 2012-07 | null or fewer | |
| 2012-08 | null or fewer | |
| 2012-09 | null or fewer | |
| 2012-10 | 6 | 0 |
Products
The products that kept showing up in Vwar's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Vwar.
- CVE-2010-5064Multiple cross-site scripting (XSS) vulnerabilities in Virtual War (aka VWar) 1.6.1 R2 allow remote attackers to inject arbitrary web script or HTML via (1) the Additional Information field to chal...4.3
- CVE-2010-5066The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to select the seed argument for the PHP mt_srand function, which m...4.3
- CVE-2010-5067Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for remote attackers to bypass timeout and logout actions, and retain access...6.8
- CVE-2010-5065popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news posts via a modified newsid parameter in a printnews action.5.0
- CVE-2010-5063SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the ratearticleselect parameter.7.5
- CVE-2010-5279article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to cause a denial of service (memory consumption) via a large integer in the ratearticleselect parameter.5.0
- CVE-2011-3813Virtual War (aka VWar) 1.5.0r15 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated...5.0
- CVE-2008-0753SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter.7.5
- CVE-2007-4605PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter, a...7.5
- CVE-2007-2312Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the n parameter to extra/online.php and o...7.5
- CVE-2007-2306Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allow remote attackers to inject arbitrary...4.3
- CVE-2006-4224Cross-site scripting (XSS) vulnerability in calendar.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the year parameter. NOTE: The pa...4.3
- CVE-2006-4142SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQL commands via the n parameter.7.5
- CVE-2006-4141SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) sortby and (2) sortorder parameters.7.5
- CVE-2006-4010SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: other vectors are covered by ...7.5
The record
- Peak rank
- #18 in Oct 2012
- Busiest month shown
- Oct 2012, 6 CVEs
- Months with a KEV entry
- 0 since Mar 2006
- Monthly snapshots
- 5 since 2006