Greg Donald has released a small set of web-scripting and link-management tools, including Destiney Links, Destiney Rated Images, and PHPLinks, that have surfaced vulnerabilities centered on information disclosure and sensitive data exposure. The products' durable exposure pattern reflects the application-layer architecture and data-handling demands of web-facing catalog and aggregation utilities. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Greg Donald over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1577MEDIUM index.php in PHP Links allows remote attackers to gain sensitive information via an invalid show parameter, which reveals the full path in an error message. | Dec 31, 2004 | 5.0 | 19 | NO | NO |
CVE-2006-2585MEDIUM SQL injection vulnerability in Destiney Links Script 2.1.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the provenance of this information | May 25, 2006 | 6.4 | 17 | NO | NO |
CVE-2006-2532MEDIUM stats.php in Destiney Rated Images Script 0.5.0 allows remote attackers to obtain the installation path via an invalid s parameter, which displays the path in an error message. NO | May 22, 2006 | 6.4 | 17 | NO | NO |
CVE-2006-2533MEDIUM Cross-site scripting (XSS) vulnerability in (1) addWeblog.php and (2) leaveComments.php in Destiney Rated Images Script 0.5.0 does not properly filter all vulnerable HTML tags, whi | May 22, 2006 | 5.8 | 16 | NO | NO |
CVE-2006-2536MEDIUM Cross-site scripting (XSS) vulnerability in Destiney Links Script 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) "Search" (term parameter in index | May 22, 2006 | 5.8 | 16 | NO | NO |
CVE-2006-2534MEDIUM Destiney Links Script 2.1.2 does not protect library and other support files, which allows remote attackers to obtain the installation path via a direct URL to files in the (1) inc | May 22, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-2535MEDIUM index.php in Destiney Links Script 2.1.2 allows remote attackers to obtain the installation path via an invalid show parameter referencing a non-existent file, which reveals the pa | May 22, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Greg Donald.
Media articles that mention a CVE ID that affects a product developed by Greg Donald — matched by CVE ID, not by vendor name.