Free PHP Scripts produces a small line of web-hosting and community-management applications such as image hosting, file hosting, and school board platforms that serve niche deployment contexts. The vendor's disclosed vulnerabilities center on code-injection weaknesses inherent to dynamic PHP application development, and public exploit code for these flaws circulates readily. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Free Php Scripts over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5764HIGH PHP remote file inclusion vulnerability in contact.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP para | Nov 6, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-5670HIGH PHP remote file inclusion vulnerability in forgot_pass.php in Free Image Hosting 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP | Nov 3, 2006 | 7.5 | 29 | NO | YES |
CVE-2007-1715HIGH PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP p | Mar 27, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-5762MEDIUM PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP | Nov 6, 2006 | 5.1 | 24 | NO | YES |
CVE-2006-5763MEDIUM Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP | Nov 6, 2006 | 5.1 | 24 | NO | YES |
CVE-2007-2626HIGH SQL injection vulnerability in admin.php in SchoolBoard allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. NOTE: CVE dispu | May 11, 2007 | 7.5 | 19 | NO | NO |
CVE-2006-5671HIGH PHP remote file inclusion vulnerability in contact.php in Free Image Hosting 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP par | Nov 3, 2006 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Free Php Scripts.
Media articles that mention a CVE ID that affects a product developed by Free Php Scripts — matched by CVE ID, not by vendor name.