Mrcgiguy maintains a small portfolio of web-based ticket, link management, and guestbook applications that have accumulated vulnerabilities concentrated in input-handling and data-exposure issues. The vendor's disclosures recur around SQL injection, cross-site scripting, and sensitive information exposure—typical of server-side web applications with insufficient input sanitization and access controls—and frequently acquire public exploit code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mrcgiguy over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2080HIGH admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration information via the editconfig ac | Jun 16, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-7120HIGH SQL injection vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to execute arbitrary SQL commands via the news.php parameter. | Aug 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-2639HIGH SQL injection vulnerability in admin.php in MRCGIGUY The Ticket System 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewticket action. | Jul 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2006-7086MEDIUM The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote attackers to obtain sensitive information and download the database via a direct request with a modified dl | Mar 2, 2007 | 4.3 | 22 | NO | YES |
CVE-2010-4500MEDIUM Multiple SQL injection vulnerabilities in contact.php in MRCGIGUY (MCG) FreeTicket 1.0.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL command | Dec 8, 2010 | 6.8 | 21 | NO | NO |
CVE-2010-4363MEDIUM Multiple SQL injection vulnerabilities in contact.php in MRCGIGUY (MCG) FreeTicket 1.0.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL command | Dec 1, 2010 | 6.8 | 21 | NO | NO |
CVE-2010-4358MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in gb.cgi in MRCGIGUY (MCG) Guestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) em | Dec 1, 2010 | 4.3 | 16 | NO | NO |
CVE-2008-7121MEDIUM Cross-site scripting (XSS) vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the search bar. | Aug 28, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mrcgiguy.
Media articles that mention a CVE ID that affects a product developed by Mrcgiguy — matched by CVE ID, not by vendor name.