Apache2triad is a web application framework with a narrow product footprint, and its vulnerability exposure centers on the single flagship product carrying recurring application-layer weaknesses. The durable signal reflects web-tier input handling and session management issues, specifically cross-site request forgery, code injection, cross-site scripting, and session fixation vulnerabilities characteristic of server-side web frameworks. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apache2triad over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12965CRITICAL Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter. | Aug 23, 2017 | 9.8 | 42 | NO | YES |
CVE-2017-12970HIGH Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authentication of authenticated users for requests that (1) add or (2) d | Aug 23, 2017 | 8.8 | 37 | NO | YES |
CVE-2017-12971MEDIUM Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account parameter to phpsftpd/users.php. | Aug 23, 2017 | 6.1 | 25 | NO | YES |
CVE-2006-0144HIGH The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious | Jan 9, 2006 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apache2triad.
Media articles that mention a CVE ID that affects a product developed by Apache2triad — matched by CVE ID, not by vendor name.