Php.S3 develops a small portfolio of web-based bulletin board and community software products, including php-i-board and Tree BBS, that rely on server-side templating and file-system operations. Its observed vulnerabilities center on input-sanitization and path-traversal weaknesses typical of web applications that generate dynamic pages and access files based on user input. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Php.S3 over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2222MEDIUM Directory traversal vulnerability in PHP-I-BOARD 1.2 and earlier allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors, probably | Jun 26, 2009 | 5.0 | 15 | NO | NO |
CVE-2009-2221MEDIUM Cross-site scripting (XSS) vulnerability in PHP-I-BOARD 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jun 26, 2009 | 4.3 | 15 | NO | NO |
CVE-2009-2226MEDIUM Cross-site scripting (XSS) vulnerability in Let's PHP! Tree BBS 2004/11/23 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jun 26, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Php.S3.
Media articles that mention a CVE ID that affects a product developed by Php.S3 — matched by CVE ID, not by vendor name.