Phpcredo develops a narrowly focused web application product—PHCDownload—that experiences recurring vulnerabilities in common application-layer input-handling mechanisms such as cross-site scripting and SQL injection. The vendor's disclosures frequently acquire public exploit code, reflecting the relative simplicity and accessibility of web application flaws to security researchers and tool developers. Defenders should treat web-facing instances of this product as a patching priority and apply input validation and parameterized-query best practices; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpcredo over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6596HIGH SQL injection vulnerability in admin/index.php in PHCDownload 1.1 allows remote attackers to execute arbitrary SQL commands via the hash parameter. NOTE: the provenance of this in | Apr 3, 2009 | 7.5 | 28 | NO | YES |
CVE-2007-6670HIGH SQL injection vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to execute arbitrary SQL commands via the string parameter. | Jan 8, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-6597MEDIUM Cross-site scripting (XSS) vulnerability in upload/install/index.php in PHCDownload 1.1 allows remote attackers to inject arbitrary web script or HTML via the step parameter. NOTE | Apr 3, 2009 | 4.3 | 21 | NO | YES |
CVE-2007-6669MEDIUM Cross-site scripting (XSS) vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the string parameter. | Jan 8, 2008 | 4.3 | 21 | NO | YES |
CVE-2006-3525HIGH SQL injection vulnerability in category.php in PHCDownload 1.0.0 Final and 1.0.0 Release Candidate 6 and earlier allows remote attackers to execute arbitrary SQL commands via the i | Jul 12, 2006 | 7.5 | 19 | NO | NO |
CVE-2007-6588MEDIUM Cross-site scripting (XSS) vulnerability in PHCDownload 1.10 allows remote attackers to inject arbitrary web script or HTML via the username field in an unspecified component. NOT | Dec 28, 2007 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpcredo.
Media articles that mention a CVE ID that affects a product developed by Phpcredo — matched by CVE ID, not by vendor name.