Bluevirus Design maintains a narrow product portfolio centered on database and file-exploration tools such as SMA DB and PH PExplorer, representing a focused rather than broadly deployed attack surface. The observed vulnerabilities cluster around these specialized applications; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bluevirus Design over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-0797HIGH PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pf | Feb 6, 2007 | 7.5 | 29 | NO | YES |
CVE-2009-1452HIGH Multiple PHP remote file inclusion vulnerabilities in theme/format.php in SMA-DB 0.3.13 allow remote attackers to execute arbitrary PHP code via a URL in the (1) _page_css and (2) | Apr 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-1450HIGH PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP code via a URL in the _page_content parameter. | Apr 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2006-5510MEDIUM Directory traversal vulnerability in explorer_load_lang.php in PH Pexplorer 0.24 allows remote attackers to include arbitrary local files via ".." sequences in the Language cookie, | Oct 25, 2006 | 6.4 | 26 | NO | YES |
CVE-2009-1451MEDIUM Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | Apr 28, 2009 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bluevirus Design.
Media articles that mention a CVE ID that affects a product developed by Bluevirus Design — matched by CVE ID, not by vendor name.