Maran's vulnerability profile centers on a small portfolio of PHP-based web applications, including a shop, blog, and forum product line, with a durable signal pointing to improper input handling in database queries. The recurring weakness class of SQL injection reflects the characteristic risks of server-side web application development where user-supplied input reaches database commands. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maran over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4880HIGH SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879. | Nov 4, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-6296HIGH admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo." | Feb 26, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-4879HIGH SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2008-4880. | Nov 4, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-2182MEDIUM Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a trailing %00 in a filename in t | Apr 24, 2007 | 6.8 | 28 | NO | YES |
CVE-2007-3198MEDIUM Cross-site scripting (XSS) vulnerability in comments.php in Maran PHP Blog (Maran Blog), possibly only versions before 20070610, allows remote attackers to inject arbitrary web scr | Jun 12, 2007 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maran.
Media articles that mention a CVE ID that affects a product developed by Maran — matched by CVE ID, not by vendor name.