Assetman is an asset management application with a compact vulnerability footprint centered on its core product, where the durable signal reflects application-layer input-handling weaknesses such as SQL injection. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Assetman over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4161MEDIUM SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks via a combination of c | Sep 22, 2008 | 6.8 | 28 | NO | YES |
CVE-2007-1427MEDIUM Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the pdf_file parameter. | Mar 13, 2007 | 5.0 | 23 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Assetman.
Media articles that mention a CVE ID that affects a product developed by Assetman — matched by CVE ID, not by vendor name.