Elinestudio's vulnerability footprint centers on its Site Composer web-development platform, with the durable signal centered on web-application layer issues including sensitive information exposure, path traversal, cross-site scripting, and SQL injection. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elinestudio over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2863HIGH Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directories via a full pathname in the | Jun 25, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-2862HIGH Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to ansFA | Jun 25, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-2864MEDIUM eLineStudio Site Composer (ESC) 2.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) trigger.asp or (2) common2.asp in cms/include/, | Jun 25, 2008 | 5.0 | 23 | NO | YES |
CVE-2008-2861MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) top | Jun 25, 2008 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elinestudio.
Media articles that mention a CVE ID that affects a product developed by Elinestudio — matched by CVE ID, not by vendor name.