- EPSS 0.48%
- Veröffentlicht 08.10.2012 10:47:44
- Zuletzt bearbeitet 11.04.2025 00:51:21
article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to cause a denial of service (memory consumption) via a large integer in the ratearticleselect parameter.
CVE-2010-5067
- EPSS 0.23%
- Veröffentlicht 08.10.2012 10:47:44
- Zuletzt bearbeitet 11.04.2025 00:51:21
Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for remote attackers to bypass timeout and logout actions, and retain access for a long period of time, by leveraging knowledge o...
CVE-2010-5066
- EPSS 0.25%
- Veröffentlicht 08.10.2012 10:47:44
- Zuletzt bearbeitet 11.04.2025 00:51:21
The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to select the seed argument for the PHP mt_srand function, which makes it easier for remote attackers to determine rand...
- EPSS 0.18%
- Veröffentlicht 08.10.2012 10:47:44
- Zuletzt bearbeitet 11.04.2025 00:51:21
popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news posts via a modified newsid parameter in a printnews action.
CVE-2010-5064
- EPSS 0.23%
- Veröffentlicht 08.10.2012 10:47:44
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in Virtual War (aka VWar) 1.6.1 R2 allow remote attackers to inject arbitrary web script or HTML via (1) the Additional Information field to challenge.php, the (2) Additional Information or (3) Cont...
CVE-2010-5063
- EPSS 0.42%
- Veröffentlicht 08.10.2012 10:47:44
- Zuletzt bearbeitet 11.04.2025 00:51:21
SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the ratearticleselect parameter.
- EPSS 0.28%
- Veröffentlicht 24.09.2011 00:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Virtual War (aka VWar) 1.5.0r15 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/language/dutch.inc.php and certain other...
CVE-2008-0753
- EPSS 0.27%
- Veröffentlicht 13.02.2008 20:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter.
CVE-2007-4605
- EPSS 3.62%
- Veröffentlicht 31.08.2007 00:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter, a different vector than CVE-2006-1503, CVE-2006-1636, ...
CVE-2007-2306
- EPSS 0.41%
- Veröffentlicht 26.04.2007 21:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) memberlist parameter ...