VendorsPaid to read script Projectpaid_to_read_script2.0.5
Vulnerabilities

Paid to read script Project Paid to read script 2.0.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2017-17651
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.
Published 2017-12-18 · Modified
9.81 PoCEPSS 0.031
CVE-2017-17777
Paid To Read Script 2.0.5 has authentication bypass in the admin panel via a direct request, as demonstrated by the admin/viewvisitcamp.php fn parameter and the admin/userview.php uid parameter.
Published 2017-12-20 · Modified
9.8EPSS 0.015
CVE-2017-17779
Paid To Read Script 2.0.5 has SQL injection via the referrals.php id parameter.
Published 2017-12-20 · Modified
9.8EPSS 0.011
CVE-2017-17776
Paid To Read Script 2.0.5 has full path disclosure via an invalid admin/userview.php uid parameter.
Published 2017-12-20 · Modified
5.3EPSS 0.009
CVE-2017-17778
Paid To Read Script 2.0.5 has XSS via the referrals.php tier parameter or the admin/userview.php uid parameter.
Published 2017-12-20 · Modified
4.8EPSS 0.005