phpMyFAQ

phpMyFAQ is an open source FAQ system using PHP. phpMyFAQ is a multilingual completely database-driven FAQ-system. It supports various databases to store all data PHP 5.3.3 (or higher) is needed in order to access this data. phpMyFAQ also offers a multi-language Content Management-System with a WYSIWYG editor and an Image Manager flexible multi-user support with user and group based permissions

Severity Summary:

Critical: 12 High: 24 Medium: 85 Low: 2
Reference
Title
Severity
phpMyFAQ Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability
Critical
phpMyFAQ Weak Password Requirements Vulnerability
Critical
phpMyFAQ Insufficient Session Expiration Vulnerability
Critical
phpMyFAQ Unrestricted Upload of File with Dangerous Type Vulnerability
Critical
phpMyFAQ Improper Neutralization of Formula Elements in a CSV File Vulnerability
Critical
phpMyFAQ Improper Access Control Vulnerability
Critical
phpMyFAQ Authentication Bypass by Capture-replay Vulnerability
Critical
phpMyFAQ Weak Password Requirements Vulnerability
Critical
phpMyFAQ Weak Password Requirements Vulnerability
Critical
phpMyFAQ Improper Control of Generation of Code (Code Injection) Vulnerability
Critical
phpMyFAQ Improper Authentication Vulnerability
Critical
phpMyFAQ Improper Restriction of Excessive Authentication Attempts Vulnerability
Critical
phpMyFAQ Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
phpMyFAQ Other Vulnerability
High
phpMyFAQ Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
High
phpMyFAQ Cleartext Transmission of Sensitive Information Vulnerability
High
phpMyFAQ Improper Neutralization of Formula Elements in a CSV File Vulnerability
High
phpMyFAQ Weak Password Requirements Vulnerability
High
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability
High
phpMyFAQ Improper Control of Generation of Code (Code Injection) Vulnerability
High
phpMyFAQ Improper Privilege Management Vulnerability
High
phpMyFAQ Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
phpMyFAQ Unrestricted Upload of File with Dangerous Type Vulnerability
High
phpMyFAQ Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
phpMyFAQ Improper Control of Generation of Code (Code Injection) Vulnerability
High
phpMyFAQ Uncaught Exception Vulnerability
High
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability
High
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability
High
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability
High
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability
High