Hotwebscripts develops a small portfolio of web-based applications including content management and rental management systems that acquire vulnerabilities centered on SQL injection and related input-handling flaws. Despite modest disclosure volume, the vendor's vulnerabilities have shown a tendency to acquire public exploit code, making timely patching important for operators of these platforms. Live severity, exploitation activity, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hotwebscripts over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4737HIGH SQL injection vulnerability in resorts.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropResort parameter. | Feb 16, 2011 | 7.5 | 32 | NO | YES |
CVE-2009-3343HIGH SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropId parameter. | Sep 24, 2009 | 7.5 | 28 | NO | YES |
CVE-2010-4703HIGH SQL injection vulnerability in default.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PageId parameter. NOTE: the provenance | Jan 20, 2011 | 7.5 | 23 | NO | NO |
CVE-2006-3135HIGH Multiple SQL injection vulnerabilities in CMS Mundo 1.0 build 008, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) news_id paramet | Jul 13, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-2911HIGH SQL injection vulnerability in controlpanel/index.php in CMS Mundo before 1.0 build 008 allows remote attackers to execute arbitrary SQL commands via the username parameter. | Jun 21, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-2684MEDIUM Cross-site scripting (XSS) vulnerability in the search module in CMS Mundo 1.0 allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter. | May 31, 2006 | 5.8 | 16 | NO | NO |
CVE-2006-2931MEDIUM CMS Mundo before 1.0 build 008 does not properly verify uploaded image files, which allows remote attackers to execute arbitrary PHP code by uploading and later directly accessing | Jun 21, 2006 | 5.1 | 15 | NO | NO |
CVE-2006-2820MEDIUM Cross-site scripting (XSS) vulnerability in HotWebScripts.com Weblog Oggi 1.0 allows remote attackers to inject arbitrary web script or HTML via a comment, possibly involving a jav | Jun 5, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hotwebscripts.
Media articles that mention a CVE ID that affects a product developed by Hotwebscripts — matched by CVE ID, not by vendor name.