Haudenschilt's vulnerability footprint is concentrated in a small set of web-based applications, notably a family connections content management system and a Battlenet clan management script. The vulnerabilities recurring across these products center on application-layer input-handling and state-management weaknesses—SQL injection, code injection, and cross-site request forgery—that are characteristic of web platforms handling user-generated content and administrative operations. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Haudenschilt over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-5130MEDIUM dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the | Aug 30, 2012 | 6.8 | 59 | NO | YES |
CVE-2012-0699HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the authentication of arbitrary use | Jan 11, 2018 | 8.8 | 39 | NO | YES |
CVE-2007-4338HIGH index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's name in the value of an fcms_log | Aug 14, 2007 | 10.0 | 39 | NO | YES |
CVE-2009-2010MEDIUM Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) | Jun 8, 2009 | 6.5 | 32 | NO | YES |
CVE-2010-3419HIGH Multiple PHP remote file inclusion vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the current | Sep 16, 2010 | 7.5 | 30 | NO | YES |
CVE-2008-3556HIGH Multiple SQL injection vulnerabilities in index.php in Battle.net Clan Script 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) showmember parameter in a m | Aug 8, 2008 | 7.5 | 30 | NO | YES |
CVE-2008-2522MEDIUM SQL injection vulnerability in members.php in Battle.net Clan Script for PHP 1.5.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL | Jun 3, 2008 | 6.8 | 26 | NO | YES |
CVE-2008-2901MEDIUM Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.4 allow remote authenticated users to execute arbitrary SQL commands via the (1) address para | Jun 30, 2008 | 6.5 | 25 | NO | YES |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Haudenschilt.
Media articles that mention a CVE ID that affects a product developed by Haudenschilt — matched by CVE ID, not by vendor name.