Easyscripts maintains a narrow portfolio of web-based scripting and news management products, including its Answer and Question Script, EasyNews, and related offerings, where vulnerabilities center on web application input handling. The durable signal across this vendor's disclosures reflects recurring code-injection and SQL-injection weaknesses characteristic of script-based web applications, and public exploit code has frequently accompanied these findings. Defenders should treat patches for this vendor's products as prioritized items in environments where they are deployed; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Easyscripts over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1664HIGH myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attackers to change the password of ot | May 18, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-1957HIGH SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands via the nb parameter in voir mode. | Apr 25, 2008 | 7.5 | 28 | NO | YES |
CVE-2009-1663MEDIUM Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitrary code by uploading a file with an exe | May 18, 2009 | 6.8 | 27 | NO | YES |
CVE-2009-1655MEDIUM Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execute arbitrary SQL commands via the (1) us | May 16, 2009 | 6.5 | 27 | NO | YES |
CVE-2009-1665MEDIUM myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter without specifying any additional | May 18, 2009 | 6.4 | 26 | NO | YES |
CVE-2008-1958MEDIUM Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arbitrary code by uploading a file | Apr 25, 2008 | 6.5 | 26 | NO | YES |
CVE-2001-1525MEDIUM Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and possibly other files via a ".." in | Dec 31, 2001 | 5.0 | 23 | NO | YES |
CVE-2009-1654MEDIUM Cross-site scripting (XSS) vulnerability in questiondetail.php in Easy Scripts Answer and Question Script allows remote attackers to inject arbitrary web script or HTML via the que | May 16, 2009 | 4.3 | 22 | NO | YES |
CVE-2001-1437HIGH easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP | Dec 1, 2001 | 7.5 | 20 | NO | NO |
CVE-2001-1526MEDIUM Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit | Dec 31, 2001 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Easyscripts.
Media articles that mention a CVE ID that affects a product developed by Easyscripts — matched by CVE ID, not by vendor name.