E Friends
Vendor:
First CVE: Sep 27, 2005 · Active for 20 years
6
Total CVEs
More Total CVEs than 83% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 47% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact E Friends over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 27, 2005
20 years ago
Most Recent CVE
Nov 23, 2007
6,822 days ago
CVE Severity & Scoring
E Friends6 CVEs
33%
67%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2824HIGH SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the pack parameter in a paypal acti | May 22, 2007 | 10.0 | 36 | NO | YES |
CVE-2006-4913HIGH Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files and possibly execute arbitrary c | Sep 21, 2006 | 7.5 | 32 | NO | YES |
CVE-2007-6106HIGH SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewevent ac | Nov 23, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-3062HIGH PHP remote file inclusion vulnerability in index.php in AlstraSoft E-Friends 4.0 allows remote attackers to execute arbitrary PHP code via the mode parameter. | Sep 27, 2005 | 7.5 | 19 | NO | NO |
CVE-2007-4080MEDIUM Cross-site scripting (XSS) vulnerability in index.php AlstraSoft E-Friends allows remote attackers to inject arbitrary web script or HTML via the p_id parameter in a people_card ac | Jul 30, 2007 | 6.4 | 17 | NO | NO |
CVE-2006-2564MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in AlstraSoft E-Friends allow remote attackers to inject arbitrary web script or HTML by (1) posting a blog, (2) po | May 24, 2006 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
50.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For E Friends
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.85 | 1 | 7.5 | 9.5% | 0 | 1 |
| 4.0 | 3 | 6.1 | 1.4% | 0 | 0 |