Memht operates a web-based portal product that exhibits a consistent vulnerability pattern centered on application-layer input handling and access control, with observed weaknesses including SQL injection, cross-site request forgery, exposure of sensitive information, and improper input validation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Memht over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5132HIGH SQL injection vulnerability in inc/ajax/ajax_rating.php in MemHT Portal 4.0.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header. | Nov 18, 2008 | 7.5 | 28 | NO | YES |
CVE-2009-0372MEDIUM Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a | Jan 30, 2009 | 6.5 | 27 | NO | YES |
CVE-2008-4457MEDIUM SQL injection vulnerability in inc/inc_statistics.php in MemHT Portal 3.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL command | Oct 7, 2008 | 6.8 | 26 | NO | YES |
CVE-2010-5320MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in MemHT Portal 4.0.1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify | Jan 3, 2015 | 6.8 | 23 | NO | NO |
cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message. | Sep 22, 2008 | 2.6 | 18 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Memht.
Media articles that mention a CVE ID that affects a product developed by Memht — matched by CVE ID, not by vendor name.