Accscripts develops a line of specialized web applications spanning email, statistics, automotive inventory, and real estate management that operate in hosted environments. The vendor's vulnerability profile centers on cross-site request forgery flaws recurring across its product portfolio, a weakness class endemic to web applications lacking robust token-based request validation. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Accscripts over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4906MEDIUM Cross-site request forgery (CSRF) vulnerability in index.php in Acc PHP eMail 1.1 allows remote attackers to hijack the authentication of administrators for requests that change pa | Jun 25, 2010 | 6.8 | 29 | NO | YES |
CVE-2008-6294HIGH admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie cookie to "admin." | Feb 26, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6293HIGH admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin." | Feb 26, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6292HIGH Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) username_cookie to "admin," (2) right_cookie to "1," and (3) id_coo | Feb 26, 2009 | 7.5 | 29 | NO | YES |
CVE-2009-4905MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Acc Statistics 1.1 allow remote attackers to hijack the authentication of administrators for requests tha | Jun 25, 2010 | 6.8 | 28 | NO | YES |
CVE-2008-6291HIGH Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLETTERLOGIN cookie to "admin". | Feb 26, 2009 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Accscripts.
Media articles that mention a CVE ID that affects a product developed by Accscripts — matched by CVE ID, not by vendor name.