CVE Tools

Dcscripts

10 CVEs tracked since 2001. Since Jan 2001, none of them reached CISA KEV.

Dcscripts CVEs per month

Jan 2001 to Apr 2006. Point at a month, or focus the strip and use the arrow keys.
Dcscripts CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2001-0110
2001-02null or fewer
2001-03null or fewer
2001-04null or fewer
2001-0520
2001-06null or fewer
2001-07null or fewer
2001-08null or fewer
2001-09null or fewer
2001-10null or fewer
2001-1110
2001-12null or fewer
2002-01null or fewer
2002-02null or fewer
2002-0310
2002-04null or fewer
2002-05null or fewer
2002-0620
2002-07null or fewer
2002-08null or fewer
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-04null or fewer
2003-05null or fewer
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-01null or fewer
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-02null or fewer
2005-03null or fewer
2005-04null or fewer
2005-05null or fewer
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-09null or fewer
2005-10null or fewer
2005-11null or fewer
2005-1210
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-0420

Products

The products that kept showing up in Dcscripts's monthly top three, with their CVEs summed over those months.

  1. Dcforum65 months
  2. Dcforum 200032 months
  3. Dcforumlite21 month
  4. Dcshop22 months
  5. Dcforum\+11 month

Latest CVEs

The 10 most recently published vulnerabilities affecting Dcscripts.

  1. CVE-2006-2049Cross-site scripting (XSS) vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to inject arbitrary web script or HTML via the az parameter.4.3
  2. CVE-2006-2050SQL injection vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to execute arbitrary SQL commands via the az parameter.5.0
  3. CVE-2005-4311Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary web script or HTML via (1) the page parameter in dcboard...4.3
  4. CVE-2002-0226retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the ...7.5
  5. CVE-2002-0492dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.5.0
  6. CVE-2001-0527DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will ...10.0
  7. CVE-2001-0821The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt ...5.0
  8. CVE-2001-0437upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.5.0
  9. CVE-2001-0436dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.7.5
  10. CVE-2000-1132DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum" variable.6.4

The record

Peak rank
#13 in Nov 2001
Busiest month shown
May 2001, 2 CVEs
Months with a KEV entry
0 since Jan 2001
Monthly snapshots
7 since 2001
Dcscripts's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store