Knusperleicht's vulnerability profile centers on a small collection of web-based content-management and utility components including a shoutbox, FAQ system, file manager, guestbook, and newsletter module. While the vendor's individual disclosures remain modest in volume, the products themselves reach a notably prominent position in the vulnerability landscape, and exploit code availability for this vendor's flaws has been characteristically high. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Knusperleicht over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4007HIGH PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the GB_PATH parameter. | Aug 7, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-4008HIGH PHP remote file inclusion vulnerability in index.php in Knusperleicht Faq 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the faq_path parameter. | Aug 7, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-3982HIGH PHP remote file inclusion vulnerability in quickie.php in Knusperleicht Quickie, probably 0.2, allows remote attackers to execute arbitrary PHP code via a URL in the QUICK_PATH par | Aug 5, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-3986HIGH PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NL_PATH para | Aug 5, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-6721MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) sbNick or ( | Dec 23, 2006 | 6.8 | 26 | NO | YES |
CVE-2006-3987MEDIUM Multiple PHP remote file inclusion vulnerabilities in index.php in Knusperleicht FileManager 1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the ( | Aug 5, 2006 | 5.1 | 23 | NO | YES |
CVE-2006-3988MEDIUM PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the news_inclu | Aug 5, 2006 | 5.1 | 23 | NO | YES |
CVE-2006-3989MEDIUM PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sb_include_pat | Aug 5, 2006 | 5.1 | 23 | NO | YES |
CVE-2005-1220HIGH Shoutbox SCRIPT 3.0.2 and earlier allows remote attackers to obtain sensitive information via a direct request to db/settings.dat, which displays usernames and password hashes. | May 2, 2005 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Knusperleicht.
Media articles that mention a CVE ID that affects a product developed by Knusperleicht — matched by CVE ID, not by vendor name.