Attachmax maintains a focused product line centered on the Dolphin application, with a vulnerability profile anchored in application-layer data-handling and injection issues including SQL injection, code injection, and sensitive information exposure. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Attachmax over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4206HIGH PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP cod | Sep 24, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-4205HIGH SQL injection vulnerability in search.php Attachmax Dolphin 2.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a Search actio | Sep 24, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4207MEDIUM Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive information via a direct request, which | Sep 24, 2008 | 5.0 | 23 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Attachmax.
Media articles that mention a CVE ID that affects a product developed by Attachmax — matched by CVE ID, not by vendor name.