Esyndicat maintains a focused product line centered on directory and link-exchange solutions, with a niche but concentrated vulnerability footprint. The recurring exposure reflects application-layer weaknesses spanning improper authentication, cross-site scripting, and SQL injection, patterns common to web-facing directory and exchange services; public exploit code has frequently been available for vulnerabilities in this vendor's products. Defenders tracking this vendor should focus on application-layer input handling and authentication controls; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Esyndicat over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3299HIGH eSyndiCat 1.6 allows remote attackers to bypass authentication and gain administrative access by setting the admin_lng cookie value to 1. NOTE: the provenance of this information i | Jul 25, 2008 | 7.5 | 30 | NO | YES |
CVE-2007-6543HIGH SQL injection vulnerability in suggest-link.php in eSyndiCat Link Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | Dec 28, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-3811HIGH Multiple SQL injection vulnerabilities in eSyndiCat allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php or (2) the name parameter to page. | Jul 17, 2007 | 7.5 | 28 | NO | YES |
CVE-2011-5177MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in admin/controller.php in eSyndiCat Pro 2.3.05 allow remote attackers to inject arbitrary web script or HTML via the (1) id par | Sep 20, 2012 | 4.3 | 24 | NO | YES |
CVE-2007-2785MEDIUM manage-admins.php in eSyndiCat Pro 1.x allows remote attackers to create additional administrative accounts, and have other unspecified impact, via modified username, new_pass, new | May 21, 2007 | 6.8 | 18 | NO | NO |
CVE-2006-2578MEDIUM admin/cron.php in eSyndicat Directory 1.2, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files and possibly execut | May 24, 2006 | 5.1 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Esyndicat.
Media articles that mention a CVE ID that affects a product developed by Esyndicat — matched by CVE ID, not by vendor name.