Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Vwar Subscribe
Filtered by product Virtual War
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-3813 1 Vwar 1 Virtual War 2012-05-20 5.0 MEDIUM N/A
Virtual War (aka VWar) 1.5.0r15 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/language/dutch.inc.php and certain other files.
CVE-2005-4748 1 Vwar 1 Virtual War 2008-09-05 6.8 MEDIUM N/A
PHP remote file include vulnerability in functions_admin.php in Virtual War (VWar) 1.5.0 R10 allows remote attackers to include and execute arbitrary PHP code via unspecified attack vectors. NOTE: this issue has been referred to as XSS, but it is clear from the vendor description that it is a file inclusion problem.