VendorsVWarvirtual_war1.5.0_r10
Vulnerabilities

VWar Virtual War 1.5.0_r10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2006-1636
PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter. NOTE: this is a different vulnerability than CVE-2006-1503.
Published 2006-04-06 · Modified
7.5EPSS 0.021
CVE-2006-3139
Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) showgame, (3) sortorder, and (4) sortby parameters.
Published 2006-06-22 · Modified
7.5EPSS 0.018
CVE-2006-4142
SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQL commands via the n parameter.
Published 2006-08-14 · Modified
7.51 PoCEPSS 0.013
CVE-2005-4748
PHP remote file include vulnerability in functions_admin.php in Virtual War (VWar) 1.5.0 R10 allows remote attackers to include and execute arbitrary PHP code via unspecified attack vectors. NOTE: this issue has been referred to as XSS, but it is clear from the vendor description that it is a file inclusion problem.
Published 2006-03-30 · Modified
6.8EPSS 0.013
CVE-2006-1503
PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attackers to include and execute arbitrary PHP code via a URL in the vwar_root parameter. NOTE: this is a different vulnerability than CVE-2006-1636.
Published 2006-03-30 · Modified
5.1EPSS 0.020