Frankmancuso maintains a small portfolio of web applications including authentication, content management, and news-aggregation products that present a modest attack surface. The durable signal across these disclosures centers on SQL injection vulnerabilities, reflecting a pattern of insufficient input sanitization in database query construction. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Frankmancuso over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0740HIGH SQL injection vulnerability in login.php in BlueBird Prelease allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters. | Feb 25, 2009 | 7.5 | 32 | NO | YES |
CVE-2009-0739HIGH SQL injection vulnerability in login.php in MyNews 0.10 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters. | Feb 25, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-0738HIGH SQL injection vulnerability in login.php in Auth Php 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters. | Feb 25, 2009 | 7.5 | 28 | NO | YES |
CVE-2007-2520MEDIUM SQL injection vulnerability in admin.php in MyNews 0.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authacc cookie. | Jun 26, 2007 | 6.8 | 26 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Frankmancuso.
Media articles that mention a CVE ID that affects a product developed by Frankmancuso — matched by CVE ID, not by vendor name.