VendorsBugada Andreaphp_advanced_transfer_manager1.21
Vulnerabilities

Bugada Andrea PHP Advanced Transfer Manager 1.21

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2005-1681
PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the include_location parameter to index.php.
Published 2005-05-25 · Modified
7.51 PoCEPSS 0.066
CVE-2005-1604
PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as demonstrated using a filename ending in "php.ns", which allows execution of arbitrary PHP code.
Published 2005-05-16 · Modified
7.51 PoCEPSS 0.051
CVE-2006-1209
PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for a users/[USERNAME] file.
Published 2006-03-14 · Modified
5.01 PoCEPSS 0.034