Citrusdb
5 CVEs tracked since 2005. Since Feb 2005, none of them reached CISA KEV.
Citrusdb CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2005-02 | 5 | 0 |
Products
The products that kept showing up in Citrusdb's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 5 most recently published vulnerabilities affecting Citrusdb.
- CVE-2005-0411Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.7.5
- CVE-2005-0408CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating...9.8
- CVE-2005-0409CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information suc...6.4
- CVE-2005-0410SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file.5.0
- CVE-2005-0229CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.5.0
The record
- Peak rank
- #30 in Feb 2005
- Busiest month shown
- Feb 2005, 5 CVEs
- Months with a KEV entry
- 0 since Feb 2005
- Monthly snapshots
- 1 since 2005