2daybiz develops a narrow portfolio of web-based business and community-oriented scripts, including custom t-shirt design, video community, and polling tools that serve small-to-medium enterprises and niche markets. The vendor's vulnerability profile is characterized by a strong tendency toward public exploit availability, reflecting the application-layer nature of its products and the accessibility of these scripts to security researchers and malicious actors. Exposure recurs consistently through SQL injection and cross-site scripting weaknesses, which are endemic to web application frameworks where input validation and output encoding are not properly implemented. Defenders deploying these scripts should prioritize input sanitization and output encoding controls, and treat vendor updates as critical; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 2daybiz over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2610HIGH Multiple SQL injection vulnerabilities in 2daybiz Job Site Script allow remote attackers to execute arbitrary SQL commands via the (1) jid parameter to view_current_job.php, (2) jo | Jul 2, 2010 | 7.5 | 33 | NO | YES |
CVE-2010-5019HIGH SQL injection vulnerability in view_photo.php in 2daybiz Online Classified Script allows remote attackers to execute arbitrary SQL commands via the alb parameter. | Nov 2, 2011 | 7.5 | 32 | NO | YES |
CVE-2010-5004HIGH SQL injection vulnerability in searchvote.php in 2daybiz Polls (aka Advanced Poll) Script allows remote attackers to execute arbitrary SQL commands via the category parameter. | Nov 2, 2011 | 7.5 | 32 | NO | YES |
CVE-2010-2511HIGH SQL injection vulnerability in viewnews.php in 2daybiz Multi Level Marketing (MLM) Software allows remote attackers to execute arbitrary SQL commands via the nwsid parameter. | Jun 28, 2010 | 7.5 | 32 | NO | YES |
CVE-2010-2609HIGH SQL injection vulnerability in show_search_result.php in 2daybiz Job Search Engine Script allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | Jul 2, 2010 | 7.5 | 31 | NO | YES |
CVE-2010-2512HIGH SQL injection vulnerability in customprofile.php in 2daybiz Matrimonial Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jun 28, 2010 | 7.5 | 31 | NO | YES |
CVE-2010-2459HIGH SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter. | Jun 25, 2010 | 7.5 | 31 | NO | YES |
CVE-2010-2691HIGH Multiple SQL injection vulnerabilities in 2daybiz Custom T-Shirt Design Script allow remote attackers to execute arbitrary SQL commands via the (1) sbid parameter to products_detai | Jul 12, 2010 | 7.5 | 30 | NO | YES |
CVE-2010-2510HIGH SQL injection vulnerability in customize.php in 2daybiz Web Template Software allows remote attackers to execute arbitrary SQL commands via the tid parameter. | Jun 28, 2010 | 7.5 | 30 | NO | YES |
CVE-2010-2508HIGH SQL injection vulnerability in user-profile.php in 2daybiz Video Community Portal Script allows remote attackers to execute arbitrary SQL commands via the userid parameter. | Jun 28, 2010 | 7.5 | 30 | NO | YES |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 2daybiz.
Media articles that mention a CVE ID that affects a product developed by 2daybiz — matched by CVE ID, not by vendor name.