Jiro's vulnerability profile centers on a focused set of web-facing administrative and content-management components including its banner system, FAQ manager, and file-upload functionality, with a durable signal rooted in SQL injection and related input-handling flaws. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jiro over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-1213HIGH JiRo's Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direct request to certain scripts i | Mar 14, 2006 | 7.5 | 32 | NO | YES |
CVE-2007-6091HIGH Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System (JBS) 2.0, and possibly JiRo's Upload Manager (aka JiRo's Upload System or JUS), allow remote atta | Nov 22, 2007 | 7.5 | 31 | NO | YES |
CVE-2008-2691HIGH SQL injection vulnerability in read.asp in JiRo's FAQ Manager eXperience 1.0 allows remote attackers to execute arbitrary SQL commands via the fID parameter. | Jun 13, 2008 | 7.5 | 28 | NO | YES |
CVE-2005-1904HIGH SQL injection vulnerability in login.asp in JiRo's Upload System (JUS) 1 allows remote attackers to execute arbitrary SQL commands via the password parameter. | Jun 9, 2005 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jiro.
Media articles that mention a CVE ID that affects a product developed by Jiro — matched by CVE ID, not by vendor name.