Known Vulnerabilities for products from Vwar

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Vwar".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2011-3813 json Virtual War (aka VWar) 1.5.0r15 allows remote attackers to obtain sensitive information via a direct request to a .php file, ... Not Provided 2011-09-24 2026-04-29
CVE-2010-5279 json article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to cause a denial of service (memory consumption) via ... Not Provided 2012-10-08 2026-04-29
CVE-2010-5067 json Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for ... Not Provided 2012-10-08 2026-04-29
CVE-2010-5066 json The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of v... Not Provided 2012-10-08 2026-04-29
CVE-2010-5065 json popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news pos... Not Provided 2012-10-08 2026-04-29
CVE-2010-5064 json Multiple cross-site scripting (XSS) vulnerabilities in Virtual War (aka VWar) 1.6.1 R2 allow remote attackers to inject arbit... Not Provided 2012-10-08 2026-04-29
CVE-2010-5063 json SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQ... Not Provided 2012-10-08 2026-04-29
CVE-2008-0753 json SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL comman... Not Provided 2008-02-13 2026-04-23
CVE-2007-4605 json PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attacke... Not Provided 2007-08-31 2026-04-23
CVE-2007-2312 json Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to exec... Not Provided 2007-04-26 2026-04-23
CVE-2007-2306 json Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when... Not Provided 2007-04-26 2026-04-23
CVE-2006-4224 json Cross-site scripting (XSS) vulnerability in calendar.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to i... 4.3 - MEDIUM 2006-08-18 2018-10-17
CVE-2006-4142 json SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execut... 7.5 - HIGH 2006-08-14 2018-10-17
CVE-2006-4141 json SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary ... 7.5 - HIGH 2006-08-14 2018-10-17
CVE-2006-4010 json SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary S... 7.5 - HIGH 2006-08-07 2018-10-17
CVE-2006-4009 json Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject... 4.3 - MEDIUM 2006-08-07 2018-10-17
CVE-2006-3139 json Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execu... 7.5 - HIGH 2006-06-22 2018-10-18
CVE-2006-2091 json admin.php in Virtual War (VWar) 1.5 and versions before 1.2 allows remote attackers to obtain sensitive information via an in... Not Provided 2006-04-29 2025-04-03
CVE-2006-1747 json PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via... Not Provided 2006-04-12 2025-04-03
CVE-2006-1636 json PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute ar... Not Provided 2006-04-06 2025-04-03

Known software with vulnerabilities from Vwar

Type Vendor Product Version
ApplicationVwarVirtual War1.0.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report