CVE Tools

Scriptphp

8 CVEs tracked since 2006. Since Dec 2006, none of them reached CISA KEV.

Scriptphp CVEs per month

Dec 2006 to Dec 2006. Point at a month, or focus the strip and use the arrow keys.
Scriptphp CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2006-1280

Products

The products that kept showing up in Scriptphp's monthly top three, with their CVEs summed over those months.

  1. Annoncescripthp31 month
  2. Pronews31 month
  3. Messageriescripthp21 month

Latest CVEs

The 9 most recently published vulnerabilities affecting Scriptphp.

  1. CVE-2008-2280Cross-site scripting (XSS) vulnerability in admin/index.php in Script PHP PicEngine 1.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter. NOTE: the provenance of ...4.3
  2. CVE-2006-6580admin/change.php in ProNews 1.5 does not check whether a user is permitted to change news items, which allows remote attackers to add or delete information within an item, and possibly have other i...6.4
  3. CVE-2006-6520Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo parameter to (a) existepseudo.php, the...6.8
  4. CVE-2006-6519SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows remote attackers to execute arbitrary SQL commands via the aa parameter.7.5
  5. CVE-2006-6518Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo, (2) email, (3) date, (4) sujet, (5) message, (6)...6.8
  6. CVE-2006-6521SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0 allows remote attackers to execute arbitrary SQL commands via the aa parameter.7.5
  7. CVE-2006-6479Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the email parameter in (1) erreurinscription.php, (2) Te...6.8
  8. CVE-2006-6480admin/admin_membre/fiche_membre.php in AnnonceScriptHP 2.0 allows remote attackers to obtain sensitive information via the idmembre parameter, which discloses the passwords for arbitrary users.5.0
  9. CVE-2006-6478Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) email.php, the (2) no parameter in (b) voirann...7.5

The record

Peak rank
#10 in Dec 2006
Busiest month shown
Dec 2006, 8 CVEs
Months with a KEV entry
0 since Dec 2006
Monthly snapshots
1 since 2006
Scriptphp's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store