CVE Tools

Comdev

15 CVEs tracked since 2005. Since Jul 2005, none of them reached CISA KEV.

Comdev CVEs per month

Jul 2005 to Feb 2009. Point at a month, or focus the strip and use the arrow keys.
Comdev CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2005-0710
2005-0820
2005-09null or fewer
2005-10null or fewer
2005-1110
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-05null or fewer
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-1050
2006-1110
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-0510
2007-0620
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-03null or fewer
2008-0410
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-01null or fewer
2009-0210

Products

The products that kept showing up in Comdev's monthly top three, with their CVEs summed over those months.

  1. Comdev Ecommerce43 months
  2. Comdev Web Blogger22 months
  3. Comdev Csv Importer11 month
  4. Comdev Form Designer11 month
  5. Comdev Forum11 month
  6. Comdev News Publisher11 month
  7. Comdev One Admin Pro11 month
  8. Comdev Vote Caster11 month
  9. Modules Builder11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Comdev.

  1. CVE-2018-6368SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action.9.8
  2. CVE-2008-6250SQL injection vulnerability in Comdev Web Blogger 4.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter to a blog page.6.8
  3. CVE-2008-1872SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter. NOTE: some of these details are ob...7.5
  4. CVE-2007-3084PHP remote file inclusion vulnerability in sampleblogger.php in Comdev Web Blogger 4.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter, a different ve...7.5
  5. CVE-2007-3081PHP remote file inclusion vulnerability in sampleecommerce.php in Comdev eCommerce 4.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter.7.5
  6. CVE-2007-2422Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote attackers to execute arbitrary PHP code via a URL in the path[docroot] paramet...9.8
  7. CVE-2006-6045Multiple PHP remote file inclusion vulnerabilities in Comdev One Admin Pro 4.1 allow remote attackers to execute arbitrary PHP code via a URL in the path[skin] parameter to (1) adminfoot.php, (2) a...6.8
  8. CVE-2006-5440PHP remote file inclusion vulnerability in adminfoot.php in Comdev Form Designer 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[d...7.5
  9. CVE-2006-5438PHP remote file inclusion vulnerability in adminfoot.php in Comdev Forum 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] ...7.5
  10. CVE-2006-5439PHP remote file inclusion vulnerability in adminfoot.php in Comdev Misc Tools 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docr...7.5
  11. CVE-2006-5441PHP remote file inclusion vulnerability in adminfoot.php in Comdev Web Blogger 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[doc...7.5
  12. CVE-2006-5101PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1, (2) Comdev Customer Helpdesk 3.1, (3) Comdev Events Calen...7.5
  13. CVE-2005-3825SQL injection vulnerability in index.php in Comdev Vote Caster 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a result action.7.5
  14. CVE-2005-2543Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter.5.0
  15. CVE-2005-2544PHP remote file inclusion vulnerability in config.php in Comdev eCommerce 3.0 allows remote attackers to execute arbitrary PHP code via the path[docroot] parameter.5.0

The record

Peak rank
#12 in Oct 2006
Busiest month shown
Oct 2006, 5 CVEs
Months with a KEV entry
0 since Jul 2005
Monthly snapshots
9 since 2005
Comdev's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store