Vulnerabilities
Vulnerable Software
Eva-Web:  Security Vulnerabilities
Multiple PHP remote file inclusion vulnerabilities in index.php3 in EVA-Web 1.1 through 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) aide or (2) perso parameter.
CVSS Score
7.5
EPSS Score
0.044
Published
2007-06-27
Multiple cross-site scripting (XSS) vulnerabilities in EVA-Web 2.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) debut_image parameter in (a) article-album.php3, (2) date parameter in (b) rubrique.php3, and the (3) perso and (4) aide parameters to (c) an unknown script, probably index.php.
CVSS Score
6.8
EPSS Score
0.006
Published
2006-05-31
An unspecified script in EVA-Web 2.1.2 and earlier, probably index.php, allows remote attackers to obtain the full path of the web server via invalid (1) perso or (2) aide parameters.
CVSS Score
7.8
EPSS Score
0.005
Published
2006-05-31


Contact Us

Shodan ® - All rights reserved