Phpadsnew is a modestly represented advertising management platform that, despite a narrow product scope, sits prominently in the landscape of legacy web applications. Its vulnerability profile centers on a single product and recurs through application-layer weaknesses including SQL injection, code injection, and exposure of sensitive information—patterns typical of server-side PHP code handling user input and template data. The vendor's disclosures frequently acquire public exploit tooling, making timely patching important for deployments; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpadsnew over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3984HIGH PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later versions, with phpAdsNew 2.0.5, allows remote attackers to execu | Aug 5, 2006 | 7.5 | 29 | NO | YES |
CVE-2005-2636HIGH SQL injection vulnerability in lib-view-direct.inc.php in phpAdsNew and phpPgAds before 2.0.6 allows remote attackers to execute arbitrary SQL commands via the clientid parameter. | Aug 23, 2005 | 7.5 | 22 | NO | NO |
CVE-2005-0791MEDIUM Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via | Mar 14, 2005 | 4.3 | 22 | NO | YES |
CVE-2001-1054HIGH PHPAdsNew PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | Oct 2, 2001 | 7.5 | 21 | NO | NO |
CVE-2007-0486HIGH Multiple PHP remote file inclusion vulnerabilities in Openads (aka phpAdsNew) 2.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) phpAds_geoPlugin param | Jan 25, 2007 | 7.5 | 20 | NO | NO |
CVE-2005-3646HIGH Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote attackers to execute arbitrary SQL command | Nov 17, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-0790MEDIUM phpAdsNew 2.0.4 allows remote attackers to obtain sensitive information via a direct request to (1) lib-xmlrpcs.inc.php, (2) maintenance-activation.php, (3) maintenance-cleantables | Mar 14, 2005 | 5.0 | 20 | NO | NO |
CVE-2006-6415HIGH PHP remote file inclusion vulnerability in admin/lib-maintenance.inc.php in phpAdsNew 2.0.4-pr2 allows remote attackers to execute arbitrary PHP code via a URL in the phpAds_path p | Dec 10, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-5437MEDIUM Directory traversal vulnerability in upgrade.php in phpAdsNew 2.0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the phpAds_config[language] parameter. NO | Oct 20, 2006 | 5.0 | 15 | NO | NO |
CVE-2005-3791MEDIUM HTTP response splitting vulnerability in phpAdsNew and phpPgAds 2.0.6 and earlier allows remote attackers to inject arbitrary HTML headers via adclick.php and possibly other unspec | Nov 24, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpadsnew.
Media articles that mention a CVE ID that affects a product developed by Phpadsnew — matched by CVE ID, not by vendor name.