← Back

Pc4arb

pc4arb

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Pc4 Uploader
pc4_uploader

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pc4arb
1Pc4 Uploader
Apr 23, 2026
Jun 23, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) absolute path in the file parameter.
1Pc4arb
1Pc4 Uploader
Apr 23, 2026
May 20, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, a...Show more
code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, as demonstrated via the "UNIunionON" string, which is collapsed into "UNION" by the filter_sql function.Show less