Easysitenetwork develops a narrow line of content-management and website-builder products targeting niche consumer verticals such as jokes, cheats, recipes, and riddles. The vulnerability profile centers on application-layer input-handling flaws, specifically SQL injection and cross-site scripting, which are endemic to web templates that process user-supplied content with minimal sanitization. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Easysitenetwork over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5174HIGH SQL injection vulnerability in joke.php in Jokes Complete Website 2.1.3 allows remote attackers to execute arbitrary SQL commands via the jokeid parameter. | Nov 19, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-6880HIGH SQL injection vulnerability in joke.php in EasySiteNetwork Free Jokes Website allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jul 30, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-5170HIGH SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter. | Nov 19, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5169HIGH SQL injection vulnerability in drinks/drink.php in Drinks Complete Website 2.1.0 allows remote attackers to execute arbitrary SQL commands via the drinkid parameter. | Nov 19, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5168HIGH SQL injection vulnerability in tip.php in Tips Complete Website 1.2.0 allows remote attackers to execute arbitrary SQL commands via the tipid parameter. | Nov 19, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5166HIGH SQL injection vulnerability in riddle.php in Riddles Website 1.2.1 allows remote attackers to execute arbitrary SQL commands via the riddleid parameter. | Nov 19, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-0453MEDIUM SQL injection vulnerability in list.php in Easysitenetwork Recipe allows remote attackers to execute arbitrary SQL commands via the categoryid parameter. | Jan 25, 2008 | 6.8 | 26 | NO | YES |
CVE-2010-1111MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Jokes Complete Website allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to joke.php and | Mar 25, 2010 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Easysitenetwork.
Media articles that mention a CVE ID that affects a product developed by Easysitenetwork — matched by CVE ID, not by vendor name.