CVE Tools

Bosdev

12 CVEs tracked since 2004. Since Mar 2004, none of them reached CISA KEV.

Bosdev CVEs per month

Mar 2004 to Mar 2009. Point at a month, or focus the strip and use the arrow keys.
Bosdev CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2004-0310
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-02null or fewer
2005-03null or fewer
2005-04null or fewer
2005-05null or fewer
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-09null or fewer
2005-10null or fewer
2005-1110
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-05null or fewer
2006-06null or fewer
2006-0710
2006-0810
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-1130
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-0320
2008-0410
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-1010
2008-11null or fewer
2008-12null or fewer
2009-01null or fewer
2009-02null or fewer
2009-0310

Products

The products that kept showing up in Bosdev's monthly top three, with their CVEs summed over those months.

  1. Bosdates44 months
  2. Bosnews32 months
  3. Bosclassifieds Classified Ads22 months
  4. Bos Classifieds11 month
  5. Bosclassifieds Ads Systems11 month
  6. Bosmarket Business Directory System11 month

Latest CVEs

The 12 most recently published vulnerabilities affecting Bosdev.

  1. CVE-2008-6526SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2008-1838.7.5
  2. CVE-2008-4703SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article parameter.7.5
  3. CVE-2008-1838SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php.7.5
  4. CVE-2008-1224Cross-site scripting (XSS) vulnerability in account.php in BosClassifieds Classified Ads System 3.0 allows remote attackers to inject arbitrary web script or HTML via the returnTo parameter. NOTE:...4.3
  5. CVE-2008-1211Cross-site scripting (XSS) vulnerability in BosDates 3.x and 4.x allows remote attackers to inject arbitrary web script or HTML via (1) the type parameter in calendar.php and (2) the category param...4.3
  6. CVE-2007-5834Cross-site scripting (XSS) vulnerability in BosDev BosNews 4 allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element in a news post.4.3
  7. CVE-2007-5835Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or creating a new admin account, which allows remote attackers to cause a denial...5.0
  8. CVE-2007-5833Multiple cross-site scripting (XSS) vulnerabilities in BosDev BosMarket Business Directory System allow remote authenticated users to inject arbitrary web script or HTML via (1) user info (account ...3.5
  9. CVE-2006-3957PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary PHP code via a URL in the insPath parameter.7.5
  10. CVE-2006-3527Multiple PHP remote file inclusion vulnerabilities in BosClassifieds Classified Ads allow remote attackers to execute arbitrary PHP code via a URL in the insPath parameter to (1) index.php, (2) rec...7.5
  11. CVE-2005-3911Multiple SQL injection vulnerabilities in calendar.php in BosDates 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) category parameters.7.5
  12. CVE-2004-0275SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.5.0

The record

Peak rank
#24 in Nov 2007
Busiest month shown
Nov 2007, 3 CVEs
Months with a KEV entry
0 since Mar 2004
Monthly snapshots
9 since 2004
Bosdev's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store