Thorsten Rinne
100 exploits
Active since Apr 2017
phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing
phpMyFAQ - SQL Injection via User-Agent Header in BuiltinCaptcha
CVSS 9.8
phpmyfaq <= 2.9.8 - Stored Cross-Site Scripting via FAQ Title Field
CVSS 6.1
phpmyfaq < 2.9.8 - Stored Cross-Site Scripting via HTML Attachment
CVSS 5.4
phpmyfaq < 2.9.8 - Cross-Site Request Forgery in admin/stat.ratings.php
CVSS 8.8
phpmyfaq < 2.9.8 - Cross-Site Request Forgery in admin/stat.main.php
CVSS 8.8
phpmyfaq < 2.9.8 - Cross-Site Request Forgery for Glossary Modification
CVSS 8.8
phpmyfaq < 2.9.8 - Cross-Site Request Forgery in admin/ajax.config.php
CVSS 8.8
phpmyfaq < 3.1.8 - Reflected Cross-Site Scripting
CVSS 6.1
phpmyfaq < 3.1.9 - Reflected Cross-Site Scripting
CVSS 6.1
phpMyFAQ >=3.2.5 <3.2.6 - Stored Cross-Site Scripting via Email Field
CVSS 5.5
phpMyFAQ < 3.2.10 - Unauthenticated File Download via FAQ Record Iframe Embed
CVSS 4.9
phpmyfaq < 4.0.18 - Unauthenticated Account Creation via WebAuthn Prepare Endpoint
CVSS 7.5
phpmyfaq < 2.9.8 - Stored Cross-Site Scripting via metaDescription or metaKeywords
CVSS 4.8
phpmyfaq < 2.9.8 - Cross-Site Request Forgery for Glossary Addition
CVSS 8.8
phpmyfaq < 2.9.8 - Cross-Site Request Forgery in admin/stat.adminlog.php
CVSS 8.8
phpMyFAQ < 2.9.8 - Cross-Site Request Forgery in admin/news.php
CVSS 8.8
phpmyfaq < 2.9.8 - Cross-Site Request Forgery in Admin Attachment Handling
CVSS 8.8
phpmyfaq < 2.9.8 - Stored Cross-Site Scripting via Admin Tags
CVSS 6.1
phpmyfaq < 2.9.6 - Cross-Site Scripting in Question Field
CVSS 6.1
phpmyfaq < 3.2.0-alpha - Stored Cross-Site Scripting
CVSS 8.4
thorsten/phpmyfaq <3.1.8 - Info Disclosure
CVSS 9.8
phpmyfaq < 3.1.8 - Stored Cross-Site Scripting
CVSS 5.4
phpmyfaq < 3.1.9 - Stored Cross-Site Scripting
CVSS 5.4
thorsten/phpmyfaq <3.1.9 - Info Disclosure
CVSS 7.5