Arabless operates a narrowly scoped product line centered on the SaphLesson application, which appears to serve educational or training contexts. Vulnerabilities affecting this vendor have frequently acquired public exploit code and predominantly cluster around SQL injection and related input-handling weaknesses, reflecting common risks in web-facing educational platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Arabless over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2835HIGH SQL injection vulnerability in saphplesson 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) forumid parameter in add.php and (2) lessid parameter in show.p | Jun 6, 2006 | 7.5 | 28 | NO | YES |
CVE-2009-2883MEDIUM SQL injection vulnerability in admin/login.php in SaphpLesson 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cp_username | Aug 20, 2009 | 6.8 | 26 | NO | YES |
CVE-2006-1420MEDIUM SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands via the lessid parameter. | Mar 28, 2006 | 5.0 | 22 | NO | YES |
CVE-2006-2279HIGH Multiple SQL injection vulnerabilities in SaphpLesson 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the Find parameter in (a) search.php, and the (2) LID and | May 10, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-2278MEDIUM SaphpLesson 3.0 does not initialize array variables, which allows remote attackers to obtain the full path via an non-array (1) hrow parameter to (a) show.php or (b) index.php; the | May 10, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-1720MEDIUM Cross-site scripting (XSS) vulnerability in search.php in SaphpLesson 3.0 allows remote attackers to inject arbitrary web script or HTML via the Word parameter. NOTE: it is possib | Apr 11, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Arabless.
Media articles that mention a CVE ID that affects a product developed by Arabless — matched by CVE ID, not by vendor name.