Accomplishtechnology's vulnerability profile concentrates in PHPMyDirectory, a web-based directory and listing management application, where the durable exposure centers on web-application input-handling weaknesses including cross-site scripting, SQL injection, and code injection. The vendor's disclosures frequently acquire public exploit code, reflecting the accessibility and appeal of web-application flaws to attackers. Defenders should treat updates to this product as a patching priority, particularly when deployed on internet-facing systems; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Accomplishtechnology over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-5288HIGH SQL injection vulnerability in page.php in phpMyDirectory 1.3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Oct 4, 2012 | 7.5 | 32 | NO | YES |
CVE-2006-2521HIGH PHP remote file inclusion vulnerability in cron.php in phpMyDirectory 10.4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter. | May 22, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-4756HIGH SQL injection vulnerability in alpha.php in phpMyDirectory 10.4.6 and earlier allows remote attackers to execute arbitrary SQL commands via the letter parameter. NOTE: the provena | Sep 13, 2006 | 7.5 | 21 | NO | NO |
CVE-2005-0896MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in review.php in phpMyDirectory 10.1.3-rel allow remote attackers to inject arbitrary web script or HTML via the (1) subcat, (2) | May 2, 2005 | 4.3 | 21 | NO | YES |
CVE-2006-4755MEDIUM Cross-site scripting (XSS) vulnerability in alpha.php in phpMyDirectory 10.4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the letter parameter. | Sep 13, 2006 | 4.3 | 14 | NO | NO |
CVE-2006-3138MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in phpMyDirectory 10.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PIC parameter in | Jun 22, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Accomplishtechnology.
Media articles that mention a CVE ID that affects a product developed by Accomplishtechnology — matched by CVE ID, not by vendor name.