Phparcadescript is a focused web-based arcade game script platform with a modestly represented but concentrated vulnerability footprint. The observed weaknesses center on SQL injection and related input-handling flaws, reflecting the interactive database-query demands of user-driven game systems; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phparcadescript over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2775HIGH SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Aug 14, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-3711HIGH SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a browse acti | Aug 19, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-1163HIGH SQL injection vulnerability in index.php in phpArcadeScript 1.0 through 3.0 RC2 allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile acti | Mar 5, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-1082MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in phpArcadeScript 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the gamename parameter | Mar 9, 2006 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phparcadescript.
Media articles that mention a CVE ID that affects a product developed by Phparcadescript — matched by CVE ID, not by vendor name.