Pd9 Software's vulnerability footprint concentrates in MegaBBS, a bulletin-board system serving niche hosting and community applications, with a durable signal in web-application input handling: cross-site scripting, SQL injection, and related neutralization issues recur across its disclosure history. The vendor's vulnerabilities frequently acquire public exploit code, making timely patching important for operators of exposed instances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pd9 Software over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2023HIGH Multiple SQL injection vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) invisible and (2) timeoffset parameters to p | Apr 30, 2008 | 7.5 | 35 | NO | YES |
CVE-2008-2022MEDIUM Mulatiple cross-site scripting (XSS) vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) toid parameter to send-pr | Apr 30, 2008 | 4.3 | 28 | NO | YES |
CVE-2008-0436MEDIUM Cross-site scripting (XSS) vulnerability in profile-upload/upload.asp in PD9 Software MegaBBS 1.5.14b allows remote attackers to inject arbitrary web script or HTML via the target | Jan 23, 2008 | 4.3 | 21 | NO | YES |
CVE-2004-2145HIGH SQL injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows remote attackers to execute arbitrary SQL commands via the (1) sortdir or (2) criteria parameter to ladder-log. | Dec 31, 2004 | 7.5 | 19 | NO | NO |
CVE-2004-2653HIGH Unspecified vulnerability in PD9 Software MegaBBS 2.0 and 2.1 allows attackers to gain privileges via unknown vectors involving (1) admin/userlevelmembers-edit.asp and (2) admin/ed | Dec 31, 2004 | 7.5 | 19 | NO | NO |
CVE-2006-0139MEDIUM The send-private-message functionality (send-private-message.asp) in PD9 Software MegaBBS 2.1 allows remote attackers to read private messages of other users via a modified replyid | Jan 9, 2006 | 5.0 | 15 | NO | NO |
CVE-2004-2146MEDIUM CRLF injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows attackers to conduct HTTP response splitting attacks via the fid parameter in a writenew action to thread-post | Dec 31, 2004 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pd9 Software.
Media articles that mention a CVE ID that affects a product developed by Pd9 Software — matched by CVE ID, not by vendor name.