Elkagroup
4 CVEs tracked since 2007. Since Jun 2007, none of them reached CISA KEV.
Elkagroup CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2007-06 | 1 | 0 |
| 2007-07 | null or fewer | |
| 2007-08 | null or fewer | |
| 2007-09 | null or fewer | |
| 2007-10 | null or fewer | |
| 2007-11 | null or fewer | |
| 2007-12 | null or fewer | |
| 2008-01 | null or fewer | |
| 2008-02 | null or fewer | |
| 2008-03 | null or fewer | |
| 2008-04 | null or fewer | |
| 2008-05 | null or fewer | |
| 2008-06 | null or fewer | |
| 2008-07 | null or fewer | |
| 2008-08 | null or fewer | |
| 2008-09 | null or fewer | |
| 2008-10 | null or fewer | |
| 2008-11 | 1 | 0 |
| 2008-12 | null or fewer | |
| 2009-01 | null or fewer | |
| 2009-02 | null or fewer | |
| 2009-03 | null or fewer | |
| 2009-04 | 1 | 0 |
| 2009-05 | null or fewer | |
| 2009-06 | null or fewer | |
| 2009-07 | null or fewer | |
| 2009-08 | null or fewer | |
| 2009-09 | null or fewer | |
| 2009-10 | null or fewer | |
| 2009-11 | null or fewer | |
| 2009-12 | null or fewer | |
| 2010-01 | 1 | 0 |
Products
The products that kept showing up in Elkagroup's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 5 most recently published vulnerabilities affecting Elkagroup.
- CVE-2009-4569SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/.7.5
- CVE-2009-2930Cross-site scripting (XSS) vulnerability in the Search feature in elka CMS (aka Elkapax) allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI.4.3
- CVE-2009-1446Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, the...6.5
- CVE-2008-5037SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.7.5
- CVE-2007-3461SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.7.5
The record
- Peak rank
- #80 in Jan 2010
- Busiest month shown
- Jun 2007, 1 CVEs
- Months with a KEV entry
- 0 since Jun 2007
- Monthly snapshots
- 4 since 2007