VendorsVlad Alexa Manciniphpfootball1.6
Vulnerabilities

Vlad Alexa Mancini Phpfootball 1.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2009-0709
SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Published 2009-02-23 · Modified
7.51 PoCEPSS 0.010
CVE-2007-0638
show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database contents) via a % (percent) character in the dbfieldv parameter.
Published 2007-01-31 · Modified
5.01 PoCEPSS 0.031
CVE-2009-0711
filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance of that information is unknown.
Published 2009-02-23 · Modified
5.01 PoCEPSS 0.012
CVE-2009-0710
Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the user parameter to login.php or (2) the dbfield parameter to filter.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Published 2009-02-23 · Modified
4.31 PoCEPSS 0.015