Vulnerabilities
Vulnerable Software
Phprofession:  Security Vulnerabilities
phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message.
CVSS Score
5.0
EPSS Score
0.05
Published
2004-12-31
SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter.
CVSS Score
7.5
EPSS Score
0.006
Published
2004-12-31
Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.
CVSS Score
4.3
EPSS Score
0.016
Published
2004-04-21


Contact Us

Shodan ® - All rights reserved