Ac4p maintains a narrowly scoped portfolio centered on mobile applications and libraries, including its Ac4p Mobile and MobileLib Gold products. The disclosed vulnerabilities recur around path-traversal conditions and associated file-access control weaknesses, reflecting the sensitivity of mobile application file handling; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ac4p over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6389MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via the (1) Taaa parameter to (a) up.php, or the (2 | Dec 8, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-5770MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via (1) Bloks, (2) Newnews, (3) lBlok, and (4) fooo | Nov 6, 2006 | 6.8 | 27 | NO | YES |
CVE-2009-3823MEDIUM Directory traversal vulnerability in myhtml.php in Mobilelib GOLD 3.0, when magic_quotes_gpc is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the G | Oct 28, 2009 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ac4p.
Media articles that mention a CVE ID that affects a product developed by Ac4p — matched by CVE ID, not by vendor name.