Built2go's vulnerability footprint centers on a collection of small web applications and content-management products including movie review, news blog, PHP link portal, and real estate listing platforms. The observed disclosures cluster around web-application input-handling weaknesses, chiefly cross-site scripting and SQL injection, which are characteristic of server-side web frameworks where user input is inadequately sanitized before rendering or database queries. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Built2go over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2008HIGH PHP remote file inclusion vulnerability in movie_cls.php in Built2Go PHP Movie Review 2B and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_pat | Apr 25, 2006 | 7.5 | 37 | NO | YES |
CVE-2008-4497HIGH SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute arbitrary SQL commands via the event_id parameter. | Oct 9, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-1248MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3 | Mar 3, 2007 | 4.3 | 22 | NO | YES |
CVE-2007-2286HIGH PHP remote file inclusion vulnerability in config.php in Built2Go PHP Link Portal 1.79 allows remote attackers to execute arbitrary PHP code via a URL in the full_path_to_db parame | Apr 26, 2007 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Built2go.
Media articles that mention a CVE ID that affects a product developed by Built2go — matched by CVE ID, not by vendor name.