Vulnerabilities (CVE)

Filtered by vendor Sisfo Kampus Subscribe
Filtered by product Sisfo Kampus
Total 6 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-6140 1 Sisfo Kampus 1 Sisfo Kampus 2023-12-10 7.5 HIGH N/A
PHP remote file inclusion vulnerability in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to execute arbitrary PHP code via a URL in the slnt parameter to (1) index.php and (2) print.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2006-6139 1 Sisfo Kampus 1 Sisfo Kampus 2023-12-10 5.0 MEDIUM N/A
Directory traversal vulnerability in downloadexcel.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the fn parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2006-6137 1 Sisfo Kampus 1 Sisfo Kampus 2023-12-10 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in Sisfo Kampus 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the (1) exec parameter to index.php or (2) print parameter to print.php, which is also accessible via the print command to index.php.
CVE-2007-4820 1 Sisfo Kampus 1 Sisfo Kampus 2023-12-10 7.5 HIGH N/A
Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly execute local PHP scripts, via the nmf parameter.
CVE-2006-6138 1 Sisfo Kampus 1 Sisfo Kampus 2023-12-10 5.0 MEDIUM N/A
Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname in the dir parameter.
CVE-2007-4895 1 Sisfo Kampus 1 Sisfo Kampus 2023-12-10 5.0 MEDIUM N/A
Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the f parameter.