Annuaire's tracked vulnerability footprint centers on directory and naming service products, with reported issues mapped to generic or placeholder weakness classifications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Annuaire over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4601HIGH SQL injection vulnerability in index.php in Annuaire 1Two 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Sep 7, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-1434MEDIUM Cross-site scripting (XSS) vulnerability in inscription.php in Annuaire (Directory) 1.0 allows remote attackers to inject arbitrary web script or HTML via the Comment Field (COMMEN | Apr 3, 2006 | 6.8 | 18 | NO | NO |
CVE-2006-1433MEDIUM Annuaire (Directory) 1.0 allows remote attackers to obtain sensitive information via a direct request to include/lang-en.php, which reveals the full installation path. | Apr 3, 2006 | 5.0 | 15 | NO | NO |
CVE-2005-1975MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index | Jun 16, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Annuaire.
Media articles that mention a CVE ID that affects a product developed by Annuaire — matched by CVE ID, not by vendor name.