Infireal's vulnerability profile centers on a small set of web-based products including MXCamArchive and SaturnCMS, with observed weaknesses clustering around injection attacks and sensitive data exposure typical of server-side application handling. The durable signal reflects input-validation gaps in SQL and code-execution contexts alongside information-disclosure risks inherent to web application architectures; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infireal over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6262HIGH SQL injection vulnerability in lib/url/meta_url.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the URL to the translate function. NOTE: the provena | Feb 24, 2009 | 7.5 | 32 | NO | YES |
CVE-2008-6955HIGH mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a | Aug 12, 2009 | 7.5 | 30 | NO | YES |
CVE-2008-6263HIGH SQL injection vulnerability in lib/user/t_user.php in SaturnCMS allows remote attackers to execute arbitrary SQL commands via the username parameter to the _userLoggedIn function. | Feb 24, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6956MEDIUM Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via t | Aug 12, 2009 | 6.5 | 27 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infireal.
Media articles that mention a CVE ID that affects a product developed by Infireal — matched by CVE ID, not by vendor name.