CVE Tools

China-on-site

9 CVEs tracked since 2005. Since Apr 2005, none of them reached CISA KEV.

China-on-site CVEs per month

Apr 2005 to Apr 2009. Point at a month, or focus the strip and use the arrow keys.
China-on-site CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2005-0410
2005-05null or fewer
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-09null or fewer
2005-10null or fewer
2005-11null or fewer
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-05null or fewer
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-03null or fewer
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-0110
2009-0220
2009-03null or fewer
2009-0450

Products

The products that kept showing up in China-on-site's monthly top three, with their CVEs summed over those months.

  1. Flexphpdirectory21 month
  2. Flexphplink21 month
  3. Flexphpnews22 months
  4. Flexcustomer0.0.611 month
  5. Flexphpic11 month
  6. Flexphpsite11 month

Latest CVEs

The 9 most recently published vulnerabilities affecting China-on-site.

  1. CVE-2008-6761Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject arbitrary PHP code into const.inc.php via the installdbname parameter (aka the ...10.0
  2. CVE-2008-6749Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) chec...6.8
  3. CVE-2008-6750Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via...6.8
  4. CVE-2008-6731Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then access...9.3
  5. CVE-2008-6730Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPLink Pro 0.0.6 and 0.0.7, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1)...6.8
  6. CVE-2008-6241Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPSite 0.0.1 and 0.0.7, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the...6.8
  7. CVE-2008-6142Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPic 0.0.4 and FlexPHPic Pro 0.0.3, and other 0.0.x versions, allow remote attackers to execute arbitrary SQL commands via (1) ...7.5
  8. CVE-2008-5927Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPNews 0.0.6 allow remote attackers to execute arbitrary SQL commands via the (1) checkuser parameter (aka username field) or (...7.5
  9. CVE-2005-1237SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.7.5

The record

Peak rank
#30 in Apr 2009
Busiest month shown
Apr 2009, 5 CVEs
Months with a KEV entry
0 since Apr 2005
Monthly snapshots
4 since 2005
China-on-site's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store