Ezonescripts develops a narrow line of web-based script products—including dating websites, link-trader platforms, and banner-exchange systems—that are commonly deployed in niches where rapid monetization and feature extensibility are prioritized over security rigor. The vendor's vulnerability profile centers on application-layer input-handling weaknesses, particularly SQL injection and cross-site scripting flaws that recur across its script products, reflecting the limited review practices typical of commodity web-application templates. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ezonescripts over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6102HIGH SQL injection vulnerability in ratelink.php in Link Trader Script allows remote attackers to execute arbitrary SQL commands via the lnkid parameter. | Feb 10, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6101HIGH SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary SQL commands via the targetid parameter. | Feb 10, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-3943HIGH SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter. | Sep 5, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-6530MEDIUM Unrestricted file upload vulnerability in editimage.php in eZoneScripts Living Local 1.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a fil | Mar 26, 2009 | 6.5 | 26 | NO | YES |
CVE-2008-6529MEDIUM Cross-site scripting (XSS) vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to inject arbitrary web script or HTML via the r parameter. | Mar 26, 2009 | 4.3 | 21 | NO | YES |
CVE-2008-6987HIGH Unrestricted file upload vulnerability in eZoneScripts Dating Website script allows remote attackers to execute arbitrary code via unknown vectors. NOTE: the provenance of this in | Aug 19, 2009 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ezonescripts.
Media articles that mention a CVE ID that affects a product developed by Ezonescripts — matched by CVE ID, not by vendor name.