Bosdev's vulnerability profile centers on a suite of web-based classifieds and content-management applications, with disclosures clustering around application-layer input-handling weaknesses such as cross-site scripting and SQL injection. The vendor's vulnerabilities frequently acquire public exploit code, reflecting the accessibility of web-facing targets and the relative ease of demonstrating input-validation flaws in production environments. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bosdev over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1838HIGH SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php. | Apr 16, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-6526HIGH SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-20 | Mar 25, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-4703HIGH SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article parameter. | Oct 23, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-3957HIGH PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary PHP code via a URL in the insPath parameter. | Aug 1, 2006 | 7.5 | 28 | NO | YES |
CVE-2005-3911HIGH Multiple SQL injection vulnerabilities in calendar.php in BosDates 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) category parame | Nov 30, 2005 | 7.5 | 28 | NO | YES |
CVE-2004-0275MEDIUM SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter. | Nov 23, 2004 | 5.0 | 28 | NO | YES |
CVE-2006-3527HIGH Multiple PHP remote file inclusion vulnerabilities in BosClassifieds Classified Ads allow remote attackers to execute arbitrary PHP code via a URL in the insPath parameter to (1) i | Jul 12, 2006 | 7.5 | 20 | NO | NO |
CVE-2008-1211MEDIUM Cross-site scripting (XSS) vulnerability in BosDates 3.x and 4.x allows remote attackers to inject arbitrary web script or HTML via (1) the type parameter in calendar.php and (2) t | Mar 8, 2008 | 4.3 | 15 | NO | NO |
CVE-2007-5835MEDIUM Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or creating a new admin account, which allows remote attackers | Nov 5, 2007 | 5.0 | 15 | NO | NO |
CVE-2008-1224MEDIUM Cross-site scripting (XSS) vulnerability in account.php in BosClassifieds Classified Ads System 3.0 allows remote attackers to inject arbitrary web script or HTML via the returnTo | Mar 10, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bosdev.
Media articles that mention a CVE ID that affects a product developed by Bosdev — matched by CVE ID, not by vendor name.