Eqdkp develops guild-management and loot-distribution tools for online gaming communities, with a focused product line centered on its core Eqdkp platform and related variants such as Attunement and Key and Eqdkp Plus. The vendor's disclosures concentrate on SQL injection and related input-handling vulnerabilities characteristic of web applications, and these flaws have frequently acquired public exploit tooling. Defenders operating these systems should prioritize input validation and access-control hardening, particularly for internet-exposed instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eqdkp over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2716MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in EQdkp 1.3.2c and earlier allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) listmemb | May 16, 2007 | 6.8 | 30 | NO | YES |
CVE-2008-2222HIGH SQL injection vulnerability in login.php in EQdkp 1.3.2f allows remote attackers to bypass EQdkp user authentication via the user_id parameter. | May 14, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-3077HIGH SQL injection vulnerability in listmembers.php in EQdkp 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the rank parameter. | Jun 6, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-0760HIGH EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which allows remote attackers to read or modify acc | Feb 6, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-2256MEDIUM PHP remote file inclusion vulnerability in includes/dbal.php in EQdkp 1.3.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the eqdkp_root_path param | May 9, 2006 | 6.4 | 28 | NO | YES |
CVE-2007-3079HIGH listmembers.php in EQdkp 1.3.2c and earlier allows remote attackers to obtain sensitive information via an invalid compare parameter, which reveals the path. | Jun 6, 2007 | 7.1 | 19 | NO | NO |
CVE-2005-2615HIGH Unknown vulnerability in session.php in EQdkp before 1.3.0 has unknown impact and attack vectors, possibly involving auto_login_id. | Aug 17, 2005 | 7.5 | 19 | NO | NO |
CVE-2007-4176MEDIUM Multiple unspecified vulnerabilities in EQDKP Plus before 0.4.4.5 have unknown impact and attack vectors. | Aug 8, 2007 | 6.8 | 18 | NO | NO |
CVE-2007-3067MEDIUM Cross-site scripting (XSS) vulnerability in the Attunement and Key Tracker 0.95 and earlier plugin for EQdkp allows remote attackers to inject arbitrary web script or HTML via unsp | Jun 6, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eqdkp.
Media articles that mention a CVE ID that affects a product developed by Eqdkp — matched by CVE ID, not by vendor name.