Mole Group's vulnerability footprint centers on a narrow range of commercial script products—travel booking, real estate, and adult portal platforms—that are distributed to third-party operators and hosted across diverse environments. The vendor's durable signal is a pronounced concentration in SQL injection vulnerabilities, a class endemic to web-facing data-driven applications and one that frequently acquires public exploit tooling. Defenders using or hosting these scripts should prioritize input-validation remediation and treat SQL injection findings as high-confidence attack vectors; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mole Group over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4675HIGH admin/admin_info/index.php in the Mole Group Gastro Portal (Restaurant Directory) Script does not require administrative authentication, which allows remote attackers to change the | Mar 5, 2010 | 7.5 | 29 | NO | YES |
CVE-2009-4674HIGH admin/admin.php in Mole Group Sky Hunter Airline Ticket Sale Script and Bus Ticket Script allows remote attackers to change an arbitrary password via a modified user_id field. | Mar 5, 2010 | 7.5 | 28 | NO | YES |
CVE-2009-4673HIGH SQL injection vulnerability in profile.php in Mole Group Adult Portal Script allows remote attackers to execute arbitrary SQL commands via the user_id parameter. | Mar 5, 2010 | 7.5 | 28 | NO | YES |
CVE-2008-6484HIGH SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attackers to execute arbitrary SQL commands via the user field. | Mar 18, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6225HIGH SQL injection vulnerability in info.php in Mole Group Airline Ticket Sale Script allows remote attackers to execute arbitrary SQL commands via the flight parameter. NOTE: the vend | Feb 20, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-5047HIGH SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote attackers to execute arbitrary SQL commands via the username parameter. | Nov 13, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5046HIGH SQL injection vulnerability in index.php in Mole Group Pizza Script allows remote attackers to execute arbitrary SQL commands via the manufacturers_id parameter. | Nov 13, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-3123HIGH SQL injection vulnerability in index.php in Mole Group Real Estate Script 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in | Jul 10, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-3124HIGH SQL injection vulnerability in index.php in Mole Group Hotel Script 1.0 allows remote attackers to execute arbitrary SQL commands via the file parameter. | Jul 10, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-3125HIGH SQL injection vulnerability in index.php in Mole Group Lastminute Script 4.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | Jul 10, 2008 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mole Group.
Media articles that mention a CVE ID that affects a product developed by Mole Group — matched by CVE ID, not by vendor name.