Citrusdb develops a narrowly scoped customer database product, with its vulnerability exposure centered on authentication and cryptographic handling weaknesses such as insufficient password-hashing computational effort. Current severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Citrusdb over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-0408CRITICAL CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileg | Feb 14, 2005 | 9.8 | 36 | NO | YES |
CVE-2005-0411HIGH Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in t | Feb 14, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-0409MEDIUM CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitiv | Feb 14, 2005 | 6.4 | 27 | NO | YES |
CVE-2005-0229MEDIUM CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to new | Apr 27, 2005 | 5.0 | 25 | NO | YES |
CVE-2005-0410MEDIUM SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file. | Feb 14, 2005 | 5.0 | 23 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Citrusdb.
Media articles that mention a CVE ID that affects a product developed by Citrusdb — matched by CVE ID, not by vendor name.