Aiocp is a niche vendor with a focused product portfolio centered on a single system or application component. Its disclosed vulnerabilities center on input-handling weaknesses, particularly SQL injection flaws characteristic of database-connected software, and frequently acquire public exploit tooling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aiocp over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5831HIGH PHP remote file inclusion vulnerability in admin/code/index.php in All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to execute arbitrary PHP code via a | Nov 10, 2006 | 7.5 | 29 | NO | YES |
CVE-2008-4782HIGH SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote attackers to execute arbitrary SQL commands via the poll_id pa | Oct 29, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-5829MEDIUM Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) choosed_language | Nov 10, 2006 | 6.8 | 28 | NO | YES |
CVE-2006-5830MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1 | Nov 10, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-5832MEDIUM All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) public/code/cp_dpage.php, possibl | Nov 10, 2006 | 5.0 | 23 | NO | YES |
CVE-2007-2624MEDIUM Dynamic variable evaluation vulnerability in shared/config/cp_config.php in All In One Control Panel (AIOCP) before 1.3.016 allows remote attackers to conduct cross-site scripting | May 11, 2007 | 6.8 | 19 | NO | NO |
CVE-2007-2625MEDIUM Cross-site scripting (XSS) vulnerability in shared/code/cp_authorization.php in All In One Control Panel (AIOCP) before 1.3.016 allows remote attackers to inject arbitrary web scri | May 11, 2007 | 6.8 | 18 | NO | NO |
CVE-2007-3120MEDIUM Cross-site scripting (XSS) vulnerability in public/code/cp_dpage.php in All In One Control Panel (AIOCP) before 1.3.017 allows remote attackers to inject arbitrary web script or HT | Jun 7, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aiocp.
Media articles that mention a CVE ID that affects a product developed by Aiocp — matched by CVE ID, not by vendor name.