2532gigs is a niche vendor with a focused product footprint centered on a single application, characterized by recurring input-handling and access-control weaknesses including path traversal, code injection, and SQL injection. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 2532gigs over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6902MEDIUM Unrestricted file upload vulnerability in upload_flyer.php in 2532designs 2532|Gigs 1.2.2 Stable allows remote attackers to execute arbitrary code by uploading a file with an execu | Aug 6, 2009 | 6.8 | 29 | NO | YES |
CVE-2007-4585HIGH Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language par | Aug 29, 2007 | 7.5 | 29 | NO | YES |
CVE-2008-6907MEDIUM Multiple SQL injection vulnerabilities in checkuser.php in 2532designs 2532|Gigs 1.2.2 Stable, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL co | Aug 6, 2009 | 6.8 | 26 | NO | YES |
CVE-2008-6901MEDIUM Multiple directory traversal vulnerabilities in 2532designs 2532|Gigs 1.2.2 Stable, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to inc | Aug 6, 2009 | 5.1 | 24 | NO | YES |
CVE-2008-6199MEDIUM 2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.php, which creates backup.sql un | Feb 20, 2009 | 4.0 | 20 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 2532gigs.
Media articles that mention a CVE ID that affects a product developed by 2532gigs — matched by CVE ID, not by vendor name.