Hinton Design's vulnerability profile centers on a collection of PHP-based web applications including phpht TopSites, phpHD, and related guest-book and status-monitoring tools that serve small- to medium-scale web communities. The recurring exposure reflects the vendor's application tier: input-handling weaknesses dominate, particularly cross-site scripting and SQL injection flaws characteristic of web-facing PHP code, alongside unclassified or placeholder categorizations in the NVD. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hinton Design over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5458HIGH PHP remote file inclusion vulnerability in common.php in Hinton Design phpht Topsites allows remote attackers to execute arbitrary PHP code via a URL in the phpht_real_path paramet | Oct 23, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-7091HIGH PHP remote file inclusion vulnerability in config.php in phpht Topsites FREE 1.022b allows remote attackers to execute arbitrary PHP code via a URL in the fullpath parameter. NOTE | Mar 2, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-0654HIGH check.php in Hinton Design phpht Topsites 1.3 does not validate passwords when using cookies, which allows remote attackers to bypass authentication via unspecified cookies. | Feb 13, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-0602HIGH Multiple SQL injection vulnerabilities in Hinton Design phphg Guestbook 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to check.php or | Feb 8, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-0604HIGH check.php in Hinton Design phphg Guestbook 1.2 does not check the user password when authenticating via cookies, which allows remote attackers to gain unauthorized access. | Feb 8, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-0607HIGH check.php in Hinton Design phphd 1.0 does not check passwords when certain cookies are provided, which allows remote attackers to bypass authentication. | Feb 8, 2006 | 7.5 | 20 | NO | NO |
CVE-2007-2096HIGH PHP remote file inclusion vulnerability in common.php in Hinton Design PHPHD Download System (phphd_downloads) allows remote attackers to execute arbitrary PHP code via a URL in th | Apr 18, 2007 | 7.5 | 19 | NO | NO |
CVE-2006-5460HIGH Multiple PHP remote file inclusion vulnerabilities in Hinton Design phpht Topsites allow remote attackers to execute arbitrary PHP code via a URL in the phpht_real_path parameter t | Oct 23, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-0653HIGH Multiple SQL injection vulnerabilities in Hinton Design phpht Topsites 1.3 allow remote attackers to execute arbitrary SQL commands via multiple vectors including the username para | Feb 13, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-0608HIGH Multiple SQL injection vulnerabilities in Hinton Design phphd 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to check.php or (2) unknow | Feb 8, 2006 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hinton Design.
Media articles that mention a CVE ID that affects a product developed by Hinton Design — matched by CVE ID, not by vendor name.