Mlffat is a focused data-handling or database-abstraction library or tool with a modestly represented but recurring presence in vulnerability disclosures, centered on its core product. The durable signal centers on SQL injection vulnerabilities, reflecting the product's interaction with database query construction and input handling. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mlffat over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2585HIGH SQL injection vulnerability in index.php in Mlffat 2.2 allows remote attackers to execute arbitrary SQL commands via a member cookie in an account editprofile action, a different v | Jul 24, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-1731HIGH SQL injection vulnerability in panel/index.php in MLFFAT 2.1 allows remote attackers to execute arbitrary SQL commands via a base64-encoded supervisor cookie. | May 20, 2009 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mlffat.
Media articles that mention a CVE ID that affects a product developed by Mlffat — matched by CVE ID, not by vendor name.