Dotbr operates a focused vulnerability footprint centered on its botbr product, with the durable pattern reflecting input-validation and information-disclosure weaknesses typical of web-facing applications. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dotbr over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1405HIGH DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3. | Dec 31, 2003 | 7.5 | 29 | NO | YES |
CVE-2003-1404HIGH DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information such as SQL usernames and pa | Dec 31, 2003 | 7.5 | 24 | NO | NO |
CVE-2003-1403HIGH foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function. | Dec 31, 2003 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dotbr.
Media articles that mention a CVE ID that affects a product developed by Dotbr — matched by CVE ID, not by vendor name.