China-on-site
9 CVEs tracked since 2005. Since Apr 2005, none of them reached CISA KEV.
China-on-site CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2005-04 | 1 | 0 |
| 2005-05 | null or fewer | |
| 2005-06 | null or fewer | |
| 2005-07 | null or fewer | |
| 2005-08 | null or fewer | |
| 2005-09 | null or fewer | |
| 2005-10 | null or fewer | |
| 2005-11 | null or fewer | |
| 2005-12 | null or fewer | |
| 2006-01 | null or fewer | |
| 2006-02 | null or fewer | |
| 2006-03 | null or fewer | |
| 2006-04 | null or fewer | |
| 2006-05 | null or fewer | |
| 2006-06 | null or fewer | |
| 2006-07 | null or fewer | |
| 2006-08 | null or fewer | |
| 2006-09 | null or fewer | |
| 2006-10 | null or fewer | |
| 2006-11 | null or fewer | |
| 2006-12 | null or fewer | |
| 2007-01 | null or fewer | |
| 2007-02 | null or fewer | |
| 2007-03 | null or fewer | |
| 2007-04 | null or fewer | |
| 2007-05 | null or fewer | |
| 2007-06 | null or fewer | |
| 2007-07 | null or fewer | |
| 2007-08 | null or fewer | |
| 2007-09 | null or fewer | |
| 2007-10 | null or fewer | |
| 2007-11 | null or fewer | |
| 2007-12 | null or fewer | |
| 2008-01 | null or fewer | |
| 2008-02 | null or fewer | |
| 2008-03 | null or fewer | |
| 2008-04 | null or fewer | |
| 2008-05 | null or fewer | |
| 2008-06 | null or fewer | |
| 2008-07 | null or fewer | |
| 2008-08 | null or fewer | |
| 2008-09 | null or fewer | |
| 2008-10 | null or fewer | |
| 2008-11 | null or fewer | |
| 2008-12 | null or fewer | |
| 2009-01 | 1 | 0 |
| 2009-02 | 2 | 0 |
| 2009-03 | null or fewer | |
| 2009-04 | 5 | 0 |
Products
The products that kept showing up in China-on-site's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 9 most recently published vulnerabilities affecting China-on-site.
- CVE-2008-6761Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject arbitrary PHP code into const.inc.php via the installdbname parameter (aka the ...10.0
- CVE-2008-6749Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) chec...6.8
- CVE-2008-6750Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via...6.8
- CVE-2008-6731Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then access...9.3
- CVE-2008-6730Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPLink Pro 0.0.6 and 0.0.7, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1)...6.8
- CVE-2008-6241Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPSite 0.0.1 and 0.0.7, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the...6.8
- CVE-2008-6142Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPic 0.0.4 and FlexPHPic Pro 0.0.3, and other 0.0.x versions, allow remote attackers to execute arbitrary SQL commands via (1) ...7.5
- CVE-2008-5927Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPNews 0.0.6 allow remote attackers to execute arbitrary SQL commands via the (1) checkuser parameter (aka username field) or (...7.5
- CVE-2005-1237SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.7.5
The record
- Peak rank
- #30 in Apr 2009
- Busiest month shown
- Apr 2009, 5 CVEs
- Months with a KEV entry
- 0 since Apr 2005
- Monthly snapshots
- 4 since 2005