CVE Tools

Exponent

16 CVEs tracked since 2005. Since Feb 2005, none of them reached CISA KEV.

Exponent CVEs per month

Feb 2005 to Apr 2007. Point at a month, or focus the strip and use the arrow keys.
Exponent CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2005-0220
2005-03null or fewer
2005-04null or fewer
2005-05null or fewer
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-09null or fewer
2005-10null or fewer
2005-1170
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-0440
2006-05null or fewer
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-0910
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-0420

Products

The products that kept showing up in Exponent's monthly top three, with their CVEs summed over those months.

  1. Exponent92 months
  2. Exponent CMS73 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Exponent.

  1. CVE-2007-2253Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol.php and (2) sdk/blanks/file_modules.php.5.0
  2. CVE-2007-2252Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive information via a .. (dot dot) in the icodir parameter.5.0
  3. CVE-2006-4963Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence in the view parameter in the show...6.4
  4. CVE-2006-1604Unspecified vulnerability in Exponent CMS before 0.96.5 RC 1 has unknown impact and remote attack vectors related to variables that are not "typecasted."10.0
  5. CVE-2006-1606Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows "directory disclosure" with unknown attack vectors.5.0
  6. CVE-2006-1605Unspecified vulnerability in the image module in Exponent CMS before 0.96.5 RC 1 allows remote attackers to execute arbitrary code via unknown vectors involving "parsed PHP."7.5
  7. CVE-2006-1607Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows "php injection" via unknown attack vectors.7.5
  8. CVE-2005-3763Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackers to obtain sensitive information. NOTE: this might be re...5.0
  9. CVE-2005-3762SQL injection vulnerability in the navigation module (navigationmodule) in Exponent CMS 0.96.3 and later versions allows remote attackers to execute arbitrary SQL commands via the parent parameter.7.5
  10. CVE-2005-3765Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to execute arbitrary code.7.5
  11. CVE-2005-3767Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and execute PHP files.5.0
  12. CVE-2005-3766Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though certain permissions are specified, which allows attackers...5.0
  13. CVE-2005-3764The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with unknown impact from the preview icon, possibly inv...10.0
  14. CVE-2005-3761Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and later versions allows remote attackers to inject arbitrary web script or HTML via (1) Javascript in forms produced by the form ge...4.3
  15. CVE-2005-0309Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) mod.php in Exponent 0.95 allow remote attackers to inject arbitrary web script or HTML via the module parameter.4.3

The record

Peak rank
#12 in Nov 2005
Busiest month shown
Nov 2005, 7 CVEs
Months with a KEV entry
0 since Feb 2005
Monthly snapshots
5 since 2005
Exponent's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store