Easy Script maintains a narrow portfolio of web application products including wiki, forum, blog, and partnership management tools. The vendor's vulnerability footprint, while limited in scope, appears across multiple small consumer and community-oriented applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Easy Script over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3200HIGH SQL injection vulnerability in vlc_forum.php in Avlc Forum as of 20080715 allows remote attackers to execute arbitrary SQL commands via the id parameter in an affich_message action | Jul 17, 2008 | 7.5 | 30 | NO | YES |
CVE-2008-5322HIGH Wysi Wiki Wyg 1.0 allows remote attackers to obtain system information via an invalid categup parameter to index.php, which calls the phpinfo function. | Dec 3, 2008 | 7.8 | 29 | NO | YES |
CVE-2008-5065HIGH TlGuestBook 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlGuestBook_login cookie to admin. | Nov 13, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-4783HIGH tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login cookie to "admin." | Oct 29, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-4781HIGH Directory traversal vulnerability in update.php in MyKtools 2.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langage parameter. | Oct 29, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-3388HIGH Multiple SQL injection vulnerabilities in Def-Blog 1.0.3 allow remote attackers to execute arbitrary SQL commands via the article parameter to (1) comaddok.php and (2) comlook.php. | Jul 30, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4780MEDIUM Directory traversal vulnerability in admin/centre.php in MyForum 1.3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via dir | Oct 29, 2008 | 6.8 | 27 | NO | YES |
CVE-2008-6165MEDIUM SQL injection vulnerability in gestion.php in CSPartner 0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) pseudo and (2) | Feb 19, 2009 | 6.8 | 26 | NO | YES |
CVE-2008-3205MEDIUM Directory traversal vulnerability in index.php in Easy-Script Wysi Wiki Wyg 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the c parameter. | Jul 17, 2008 | 5.0 | 24 | NO | YES |
CVE-2008-5323MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg 1.0 allows remote attackers to inject arbitrary web script or HTML via the s parameter. | Dec 3, 2008 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Easy Script.
Media articles that mention a CVE ID that affects a product developed by Easy Script — matched by CVE ID, not by vendor name.