Dieselscripts develops a suite of web-based job-listing, content, and traffic-management applications that demonstrate a durable vulnerability pattern centered on SQL injection and related input-handling flaws in database-connected interfaces. The vendor's disclosures frequently acquire public exploit code, reflecting the accessibility of web application attack surfaces and the straightforward nature of SQL-injection exploitation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dieselscripts over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4357HIGH PHP remote file inclusion vulnerability in clients/index.php in Diesel Smart Traffic allows remote attackers to execute arbitrary PHP code via a URL in the src parameter. | Aug 27, 2006 | 7.5 | 29 | NO | YES |
CVE-2008-6468HIGH SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the area parameter in a browse action. | Mar 13, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6467HIGH SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitrary SQL commands via the job_id parameter. | Mar 13, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-4150HIGH SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE- | Sep 24, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-3763HIGH SQL injection vulnerability in category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jul 21, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-4358MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Diesel Pay allows remote attackers to inject arbitrary web script or HTML via the read parameter. | Aug 27, 2006 | 4.3 | 21 | NO | YES |
CVE-2006-4362MEDIUM Cross-site scripting (XSS) vulnerability in getad.php in Diesel Paid Mail allows remote attackers to inject arbitrary web script or HTML via the ps parameter. | Aug 27, 2006 | 4.3 | 21 | NO | YES |
CVE-2006-2540MEDIUM Privacy leak in install.php for Diesel PHP Job Site sends sensitive information such as user credentials to an e-mail address controlled by the product developers. | May 23, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-4361MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in jobseekers/forgot.php in Diesel Job Site allow remote attackers to inject arbitrary web script or HTML via the (1) uname or ( | Aug 27, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dieselscripts.
Media articles that mention a CVE ID that affects a product developed by Dieselscripts — matched by CVE ID, not by vendor name.