Hotscripts' vulnerability profile centers on a narrow portfolio of web applications and PHP-based scripts, including community platforms like Cyboards and blog engines such as Neuron Blog, that have historically been deployed by smaller websites and forums. The exposure recurs consistently across input-handling weakness classes—path traversal, SQL injection, code injection, and cross-site scripting—reflecting the architectural patterns common to early-era PHP application development and the corresponding absence of input sanitization as standard practice. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hotscripts over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2491HIGH SQL injection vulnerability in adv_cat.php in AbleSpace 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | May 28, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-1565HIGH Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in | Mar 31, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-6084HIGH SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | Nov 22, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-6603MEDIUM Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a d | Dec 31, 2007 | 5.0 | 23 | NO | YES |
CVE-2008-3707HIGH Multiple PHP remote file inclusion vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to execute arbitrary PHP code via a URL in the script_path parameter to (1) flat | Aug 19, 2008 | 7.5 | 19 | NO | NO |
CVE-2007-4371MEDIUM Unrestricted file upload vulnerability in admin/pages/blog-add.php in Neuron Blog 1.1 allows remote attackers to upload and execute arbitrary PHP files in uploads/. | Aug 15, 2007 | 6.8 | 18 | NO | NO |
CVE-2008-3710MEDIUM Multiple directory traversal vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the | Aug 19, 2008 | 5.1 | 15 | NO | NO |
CVE-2008-3709MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to inject arbitrary web script or HTML via the (1) lOptionsOptions, (2) lNavAdm | Aug 19, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hotscripts.
Media articles that mention a CVE ID that affects a product developed by Hotscripts — matched by CVE ID, not by vendor name.