Nicecoder develops a focused line of web-facing applications, including indexU and iDesk, centered on search and desktop-management functionality where input-handling vulnerabilities recur. The vendor's disclosures cluster around classic web-application weakness classes—cross-site scripting, SQL injection, and related input-neutralization issues—and have a strong tendency toward public exploit availability. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nicecoder over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-1767HIGH Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the theme_path paramete | Apr 13, 2006 | 7.5 | 31 | NO | YES |
CVE-2006-7017HIGH Multiple PHP remote file inclusion vulnerabilities in Indexu 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the admin_template_path parameter to admin/ scr | Feb 15, 2007 | 7.5 | 30 | NO | YES |
CVE-2009-4624HIGH SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2005- | Jan 18, 2010 | 7.5 | 29 | NO | YES |
CVE-2006-0688HIGH PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path pa | Feb 15, 2006 | 7.5 | 29 | NO | YES |
CVE-2007-0364MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg para | Jan 19, 2007 | 4.3 | 21 | NO | YES |
CVE-2005-3843HIGH SQL injection vulnerability in faq.php in Nicecoder iDesk 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | Nov 26, 2005 | 7.5 | 19 | NO | NO |
CVE-2007-0349MEDIUM Directory traversal vulnerability in upgrade.php in nicecoder.com INDEXU 5.x allows remote attackers to include arbitrary local files via a .. (dot dot) in the gateway parameter. | Jan 19, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nicecoder.
Media articles that mention a CVE ID that affects a product developed by Nicecoder — matched by CVE ID, not by vendor name.