Owl maintains a focused portfolio centered on intranet and knowledge-management products, with a narrow but durable vulnerability signal around web-application input handling. The recurring weaknesses—cross-site scripting, SQL injection, and related web-layer flaws—are characteristic of platforms that integrate user-generated content and database queries, and the vendor's disclosures have frequently acquired public exploit code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Owl over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-1149HIGH PHP remote file inclusion vulnerability in lib/OWL_API.php in OWL Intranet Engine 0.82, when register_globals is enabled, allows remote attackers to include arbitrary files via a U | Mar 10, 2006 | 7.5 | 34 | NO | YES |
CVE-2008-3100MEDIUM Cross-site scripting (XSS) vulnerability in lib/owl.lib.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to inject arbit | Jul 29, 2008 | 4.3 | 21 | NO | YES |
CVE-2008-3359HIGH SQL injection vulnerability in register.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to execute arbitrary SQL comman | Jul 29, 2008 | 7.5 | 19 | NO | NO |
CVE-2005-0265HIGH Multiple SQL injection vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to execute arbitrary SQL commands via the (1) parent or (2) sortposted parameter. | May 2, 2005 | 7.5 | 19 | NO | NO |
CVE-2003-0341MEDIUM Cross-site scripting (XSS) vulnerability in Owl Intranet Engine 0.71 and earlier allows remote attackers to insert arbitrary script via the Search field. | May 21, 2003 | 6.8 | 18 | NO | NO |
CVE-2005-0264MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order p | May 2, 2005 | 4.3 | 14 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in Owl Intranet Knowledgebase 1.10 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Search fi | Dec 26, 2014 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Owl.
Media articles that mention a CVE ID that affects a product developed by Owl — matched by CVE ID, not by vendor name.