Ocean12tech maintains a focused suite of web-based business applications centered around contact, FAQ, and membership management, with a niche but durable vulnerability profile driven by input-handling weaknesses in web application layers. The vendor's disclosures cluster around SQL injection, cross-site scripting, and sensitive-information exposure—characteristic flaws in database-backed web applications where sanitization and output encoding demands are high. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ocean12tech over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6390HIGH SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenan | Mar 2, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6372HIGH SQL injection vulnerability in default.asp in Ocean12 FAQ Manager Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a Cat action. NOTE: som | Mar 2, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6371HIGH SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the username (Username parameter). | Mar 2, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6369HIGH SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitrary SQL commands via the Sort parameter. | Mar 2, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-7063MEDIUM Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for adm | Aug 25, 2009 | 5.0 | 23 | NO | YES |
CVE-2008-6370MEDIUM Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to inject arbitrary web script or HTML via the DisplayFormat par | Mar 2, 2009 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ocean12tech.
Media articles that mention a CVE ID that affects a product developed by Ocean12tech — matched by CVE ID, not by vendor name.