Blursoft maintains a narrowly scoped product portfolio centered on the Blur6EX offering, which despite minimal disclosure volume has attracted attention within its user base. The observed vulnerability signals relate to miscellaneous or unclassified weakness categories, reflecting the limited maturity of public characterization for this vendor's exposure. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blursoft over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3065HIGH SQL injection vulnerability in engine/shards/blog.php in blur6ex 0.3.462 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a proc_reply action in th | Jun 19, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-1762HIGH Directory traversal vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to include arbitrary files via the shard parameter. NOTE: this issue can be exploited to | Apr 13, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-1763MEDIUM Multiple SQL injection vulnerabilities in index.php in blur6ex 0.3.452 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a (1) g_reply or (2) g_perm | Apr 13, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-4106MEDIUM Cross-site scripting (XSS) vulnerability in blursoft blur6ex 0.3 allows remote attackers to inject arbitrary web script or HTML via a comment title. | Aug 14, 2006 | 4.3 | 14 | NO | NO |
Cross-site scripting vulnerability in index.php in blur6ex 0.3.452 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter, which is not sanitized | Apr 13, 2006 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blursoft.
Media articles that mention a CVE ID that affects a product developed by Blursoft — matched by CVE ID, not by vendor name.