Bugada Andrea maintains a narrowly scoped software offering centered on PHP Advanced Transfer Manager, a file-transfer utility that occupies a specialized niche despite appearing among more prominent vendor disclosures. The vendor's vulnerabilities have an elevated tendency toward public exploit availability, reflecting the tool's direct utility to attackers when security issues are present. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bugada Andrea over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1681HIGH PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the include_ | May 20, 2005 | 7.5 | 31 | NO | YES |
CVE-2005-1604HIGH PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as demonstrated using a filename en | May 16, 2005 | 7.5 | 30 | NO | YES |
CVE-2006-4749HIGH Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpATM) 1.20 allow remote attackers to execute arbitrary PHP code via the include_location para | Sep 13, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-4594HIGH Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpAtm) 1.21 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the | Sep 6, 2006 | 7.5 | 28 | NO | YES |
CVE-2007-2659MEDIUM Directory traversal vulnerability in index.php in PHP Advanced Transfer Manager (phpATM) 1.30 allows remote attackers to read arbitrary files and obtain script source code via a .. | May 14, 2007 | 5.0 | 25 | NO | YES |
CVE-2006-1209MEDIUM PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access control, which allows remote at | Mar 14, 2006 | 5.0 | 23 | NO | YES |
CVE-2005-2998HIGH PHP Advanced Transfer Manager 1.30 has a default password for the administrator user, which allows remote attackers to upload and execute arbitrary PHP files. | Sep 20, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-2997MEDIUM Multiple directory traversal vulnerabilities in PHP Advanced Transfer Manager 1.30 allow remote attackers to read arbitrary files via ".." sequences in (1) the currentdir parameter | Sep 20, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-2999MEDIUM PHP Advanced Transfer Manager 1.30 allows remote attackers to obtain sensitive PHP configuration information via a direct request to test.php. | Sep 20, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-3000MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in viewers/txt.php in PHP Advanced Transfer Manager 1.30 allow remote attackers to inject arbitrary web script or HTML via the ( | Sep 20, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bugada Andrea.
Media articles that mention a CVE ID that affects a product developed by Bugada Andrea — matched by CVE ID, not by vendor name.