Efiction is a niche fan-fiction platform software whose vulnerability footprint centers on its core product and reflects application-layer input-handling weaknesses, primarily SQL injection issues. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Efiction over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4171HIGH The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a | Dec 11, 2005 | 7.5 | 31 | NO | YES |
CVE-2005-4168HIGH Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let parameter in a viewlist action to titl | Dec 11, 2005 | 7.5 | 29 | NO | YES |
CVE-2005-4169HIGH Multiple SQL injection vulnerabilities in eFiction 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) let parameter in a viewlist action to authors.php and (2 | Dec 11, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-4170HIGH SQL injection vulnerability in eFiction 1.1 allows remote attackers to execute arbitrary SQL commands via the uid parameter to viewuser.php. | Dec 11, 2005 | 7.5 | 28 | NO | YES |
CVE-2007-1118MEDIUM Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path_to_smf parameter to (1) | Feb 27, 2007 | 6.8 | 27 | NO | YES |
CVE-2008-2754MEDIUM SQL injection vulnerability in toplists.php in eFiction 3.0 and 3.4.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the list par | Jun 18, 2008 | 6.8 | 26 | NO | YES |
CVE-2006-4427MEDIUM index.php in eFiction before 2.0.7 allows remote attackers to bypass authentication and gain privileges by setting the (1) adminloggedin, (2) loggedin, and (3) level parameters to | Aug 29, 2006 | 5.1 | 23 | NO | YES |
CVE-2005-4167MEDIUM Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the let parameter in a viewlist action to titles | Dec 11, 2005 | 4.3 | 22 | NO | YES |
CVE-2005-4174HIGH eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. | Dec 11, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-4173MEDIUM eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information by accessing phpinfo.php, which executes the PHP phpinfo function. | Dec 11, 2005 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Efiction.
Media articles that mention a CVE ID that affects a product developed by Efiction — matched by CVE ID, not by vendor name.