Indexcor maintains EZDatabase, a narrowly scoped database product that despite its limited footprint has attracted public exploit tooling for its disclosed vulnerabilities. The product's vulnerability profile reflects the difficulty of securing complex data-handling software, and defenders deploying this platform should monitor vendor advisories closely for remediation guidance. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Indexcor over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0214HIGH Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using | Jan 15, 2006 | 7.5 | 29 | NO | YES |
CVE-2005-4303HIGH SQL injection vulnerability in index.php for ezDatabase 2.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the db_id parameter. | Dec 17, 2005 | 7.5 | 29 | NO | YES |
CVE-2006-0315MEDIUM index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory | Jan 19, 2006 | 5.8 | 26 | NO | YES |
CVE-2005-4302MEDIUM Directory traversal vulnerability in index.php in ezDatabase 2.1.2 and earlier allows remote attackers to include arbitrary local files via ".." sequences in the p parameter. | Dec 17, 2005 | 5.0 | 23 | NO | YES |
CVE-2007-0592MEDIUM Cross-site scripting (XSS) vulnerability in EzDatabase 2.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to admin/login.php and t | Jan 30, 2007 | 6.8 | 18 | NO | NO |
CVE-2005-4304MEDIUM index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id parameter, which leaks the full pathname in an error message | Dec 17, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Indexcor.
Media articles that mention a CVE ID that affects a product developed by Indexcor — matched by CVE ID, not by vendor name.