Aspindir's vulnerability portfolio centers on a collection of web-facing applications and e-commerce platforms including Angelo Emlak, Shibby Shop, XWeblog, and Alişveriş Sitesi Script, which occupy a modest but specialized niche in the vulnerability landscape. The vendor's disclosures cluster heavily around application-layer input-handling flaws, particularly SQL injection and cross-site scripting vulnerabilities, reflecting the common weaknesses found in custom web applications and content-management systems. Notably, vulnerabilities from this vendor have a strong tendency to acquire public exploit code and tooling, making them targets for opportunistic exploitation once details emerge. Defenders operating these platforms should prioritize patching advisories and restrict direct internet exposure where feasible; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aspindir over time
Signals from CVEs in this vendor scope (41 CVEs).
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4144HIGH SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL commands via the Id parameter. | Nov 2, 2010 | 7.5 | 32 | NO | YES |
CVE-2008-3888HIGH SQL injection vulnerability in members.asp in Mini-NUKE Freehost 2.3 allows remote attackers to execute arbitrary SQL commands via the uid parameter in a member_details action. | Sep 2, 2008 | 7.5 | 32 | NO | YES |
CVE-2010-4856HIGH SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter. | Oct 5, 2011 | 7.5 | 31 | NO | YES |
CVE-2010-4855HIGH SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter. | Oct 5, 2011 | 7.5 | 31 | NO | YES |
CVE-2007-3884HIGH SQL injection vulnerability in philboard_forum.asp in husrevforum 1.0.1 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: it was later rep | Jul 18, 2007 | 7.5 | 30 | NO | YES |
CVE-2008-2882HIGH upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers to update a file or have unspecified other impact via a dir | Jun 26, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-6640HIGH Multiple SQL injection vulnerabilities in BatmanPorTaL allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) uyeadmin.asp and (2) profil.asp. NOTE: | Apr 7, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-0447HIGH Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the user parameter (aka UserName field) | Feb 10, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-5707HIGH SQL injection vulnerability in urunler.asp in Iltaweb Alisveris Sistemi allows remote attackers to execute arbitrary SQL commands via the catno parameter. | Dec 24, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5057HIGH SQL injection vulnerability in film.asp in Yigit Aybuga Dizi Portali allows remote attackers to execute arbitrary SQL commands via the film parameter. NOTE: the provenance of this | Nov 13, 2008 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (41 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aspindir.
Media articles that mention a CVE ID that affects a product developed by Aspindir — matched by CVE ID, not by vendor name.