Mnogosearch is a web search engine and indexing platform whose vulnerability profile concentrates in a single product and recurs through application-layer input-handling weaknesses, particularly cross-site scripting and SQL injection flaws. The vendor's disclosures frequently acquire public exploit code, reflecting the web-facing nature of search and indexing applications. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mnogosearch over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0437HIGH Buffer overflow in search.cgi for mnoGoSearch 3.2.10 allows remote attackers to execute arbitrary code via a long tmplt parameter. | Jul 24, 2003 | 7.5 | 38 | NO | YES |
CVE-2003-0436HIGH Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul parameter. | Jul 24, 2003 | 7.5 | 32 | NO | YES |
CVE-2004-0288HIGH Buffer overflow in the UdmDocToTextBuf function in mnoGoSearch 3.2.13 through 3.2.15 could allow remote attackers to execute arbitrary code by indexing a large document. | Nov 23, 2004 | 10.0 | 26 | NO | NO |
CVE-2011-5235HIGH SQL injection vulnerability in mnoGoSearch before 3.3.12 allows remote attackers to execute arbitrary SQL commands via the hostname in a hypertext link. | Oct 25, 2012 | 7.5 | 22 | NO | NO |
CVE-2002-0789HIGH Buffer overflow in search.cgi in mnoGoSearch 3.1.19 and earlier allows remote attackers to execute arbitrary code via a long query (q) parameter. | Aug 12, 2002 | 7.5 | 20 | NO | NO |
CVE-2007-5588MEDIUM Cross-site scripting (XSS) vulnerability in mnoGoSearch before 3.2.43 allows remote attackers to inject arbitrary web script or HTML via the t parameter in search.cgi, as reachable | Oct 19, 2007 | 4.3 | 14 | NO | NO |
CVE-2004-1059MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in mnoGoSearch 3.2.26 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) next and (2) prev r | Dec 10, 2004 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mnogosearch.
Media articles that mention a CVE ID that affects a product developed by Mnogosearch — matched by CVE ID, not by vendor name.