Boesch IT maintains a focused portfolio of web-based content and information management products, including SimpleNews, SimpleGB, and FAQ Engine, that serve niche publishing and community functions. The vendor's disclosed vulnerabilities concentrate around application-level input handling and access control in these narrowly scoped products. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Boesch It over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1360HIGH Multiple PHP remote file inclusion vulnerabilities in FAQEngine 4.24.00 allow remote attackers to execute arbitrary PHP code via a URL in the path_faqe parameter to (1) attachs.php | Apr 13, 2010 | 7.5 | 31 | NO | YES |
CVE-2010-2858MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in news.php in SimpNews 2.47.03 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) layout and | Jul 25, 2010 | 4.3 | 23 | NO | YES |
CVE-2007-4874MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in SimpNews 2.41.03 allow remote attackers to inject arbitrary web script or HTML via the (1) l_username parameter to admin/layo | Sep 26, 2007 | 4.3 | 21 | NO | YES |
CVE-2010-2859MEDIUM news.php in SimpNews 2.47.3 and earlier allows remote attackers to obtain sensitive information via an invalid lang parameter, which reveals the installation path in an error messa | Jul 25, 2010 | 5.0 | 18 | NO | NO |
CVE-2007-5128MEDIUM SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date parameter to events.php, which reveals | Sep 27, 2007 | 5.0 | 15 | NO | NO |
CVE-2007-5129MEDIUM SimpGB 1.46.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) obtain sensitive configuration information via | Sep 27, 2007 | 5.0 | 15 | NO | NO |
CVE-2007-5130MEDIUM SimpGB 1.46.02 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php or (2) a direct request to admin/trailer.php, which reve | Sep 27, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Boesch It.
Media articles that mention a CVE ID that affects a product developed by Boesch It — matched by CVE ID, not by vendor name.