Bpowerhouse develops a small suite of web-based applications spanning content management, gaming, vacation rentals, legal document handling, and music services, each presenting a distinct application surface. The vendor's vulnerability profile centers on recurrent input-handling weaknesses, particularly SQL injection and path-traversal flaws, which are characteristic of application-layer exposure in web platforms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bpowerhouse over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3503HIGH Multiple SQL injection vulnerabilities in search.aspx in BPowerHouse BPHolidayLettings 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) rid and (2) tid para | Sep 30, 2009 | 7.5 | 29 | NO | YES |
CVE-2009-3502HIGH SQL injection vulnerability in music.php in BPowerHouse BPMusic 1.0 allows remote attackers to execute arbitrary SQL commands via the music_id parameter. | Sep 30, 2009 | 7.5 | 29 | NO | YES |
CVE-2009-3500HIGH Multiple SQL injection vulnerabilities in BPowerHouse BPGames 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to main.php and (2) game_id | Sep 30, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-3499HIGH SQL injection vulnerability in employee.aspx in BPowerHouse BPLawyerCaseDocuments 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | Sep 30, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-5594HIGH Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page | Dec 16, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5593HIGH Multiple directory traversal vulnerabilities in index.php in Mini CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page a | Dec 16, 2008 | 7.5 | 28 | NO | YES |
CVE-2009-4540MEDIUM SQL injection vulnerability in page.php in Mini CMS 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jan 4, 2010 | 6.8 | 26 | NO | YES |
CVE-2009-3501HIGH SQL injection vulnerability in students.php in BPowerHouse BPStudents 1.0 allows remote attackers to execute arbitrary SQL commands via the test parameter in a preview action. | Sep 30, 2009 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bpowerhouse.
Media articles that mention a CVE ID that affects a product developed by Bpowerhouse — matched by CVE ID, not by vendor name.