Netref maintains a focused product line centered on its core netref offering, which operates despite a modest vulnerability footprint. The durable signal is anchored in application-layer input-handling weaknesses, particularly SQL injection risks, reflecting common validation gaps in web-facing or database-connected services. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netref over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1222HIGH cat_for_gen.php in Annuaire Netref 4.2 allows remote attackers to execute arbitrary PHP code by setting the ad_direct parameter to reference cat_for_gen.php, then including the cod | May 2, 2005 | 7.5 | 31 | NO | YES |
CVE-2008-5561HIGH SQL injection vulnerability in Netref 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) fiche_product.php and (2) presentation.php. | Dec 15, 2008 | 7.5 | 28 | NO | YES |
CVE-2005-4198HIGH SQL injection vulnerability in index.php in Netref 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of this issue is unknow | Dec 13, 2005 | 7.5 | 28 | NO | YES |
CVE-2006-5618MEDIUM Directory traversal vulnerability in script/cat_for_aff.php in Netref 4 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the ad_direct parameter. | Oct 31, 2006 | 5.0 | 23 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netref.
Media articles that mention a CVE ID that affects a product developed by Netref — matched by CVE ID, not by vendor name.