CVE Tools

Katywhitton

8 CVEs tracked since 2008. Since Dec 2008, none of them reached CISA KEV.

Katywhitton CVEs per month

Dec 2008 to Jan 2009. Point at a month, or focus the strip and use the arrow keys.
Katywhitton CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2008-1220
2009-0160

Products

The products that kept showing up in Katywhitton's monthly top three, with their CVEs summed over those months.

  1. Blogit\!41 month
  2. Rankem42 months

Latest CVEs

The 8 most recently published vulnerabilities affecting Katywhitton.

  1. CVE-2009-0336Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a ...5.0
  2. CVE-2009-0335Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to inject arbitrary web script or HTML via the view parameter.4.3
  3. CVE-2009-0337SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters. NOTE: the provenance of this i...7.5
  4. CVE-2009-0334SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL commands via the day parameter in an archive action.7.5
  5. CVE-2009-0248Cross-site scripting (XSS) vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to inject arbitrary web script or HTML via the siteID parameter.4.3
  6. CVE-2009-0249Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct reques...5.0
  7. CVE-2008-5588SQL injection vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to execute arbitrary SQL commands via the siteID parameter.7.5
  8. CVE-2008-5589SQL injection vulnerability in processlogin.asp in Katy Whitton RankEm allows remote attackers to execute arbitrary SQL commands via the (1) txtusername parameter (aka username field) or the (2) tx...7.5

The record

Peak rank
#10 in Jan 2009
Busiest month shown
Jan 2009, 6 CVEs
Months with a KEV entry
0 since Dec 2008
Monthly snapshots
2 since 2008
Katywhitton's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store