Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Bare Concept Media Subscribe
Filtered by product Pheap Cms
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-4531 1 Bare Concept Media 1 Pheap Cms 2018-10-17 7.5 HIGH N/A
PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter.
CVE-2006-4621 1 Bare Concept Media 1 Pheap Cms 2011-03-07 7.5 HIGH N/A
PHP remote file inclusion vulnerability in settings.php in Pheap 1.2, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The lib/config.php vector is already covered by CVE-2006-4531.