Autosectools maintains a narrowly scoped portfolio centered on its V-CMS product, a web-based content management system where the recurring vulnerability signal reflects classic application-layer input-handling weaknesses including code injection, cross-site scripting, and SQL injection. These pattern reflect the challenges of sanitizing and validating user-supplied data in web applications; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Autosectools over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4828HIGH Unrestricted file upload vulnerability in includes/inline_image_upload.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an | Dec 15, 2011 | 7.5 | 76 | NO | YES |
CVE-2011-4826MEDIUM SQL injection vulnerability in session.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to process.php. NOTE: some o | Dec 15, 2011 | 6.8 | 21 | NO | NO |
CVE-2011-4827MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in AutoSec Tools V-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) p parameter to redirect.php | Dec 15, 2011 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Autosectools.
Media articles that mention a CVE ID that affects a product developed by Autosectools — matched by CVE ID, not by vendor name.