Phplinkdirectory is a modestly deployed PHP-based web directory and link management application whose vulnerability exposures center on its web-application interface. The durable signal spans cross-site request forgery and sensitive information disclosure weaknesses, reflecting the common input-validation and state-management challenges of web applications; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phplinkdirectory over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-0643MEDIUM Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows remote attackers to hijack the authentication of administrat | Jan 25, 2011 | 6.8 | 30 | NO | YES |
CVE-2008-6851MEDIUM SQL injection vulnerability in page.php in PHP Link Directory (phpLD) 3.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arb | Jul 7, 2009 | 5.1 | 22 | NO | YES |
CVE-2011-3782MEDIUM phpLD 2-151.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrate | Sep 24, 2011 | 5.0 | 16 | NO | NO |
CVE-2007-0529MEDIUM Cross-site scripting (XSS) vulnerability in index.html (aka the administration page) in PHP Link Directory (phpLD) 3.0.6 and earlier allows remote attackers to inject arbitrary web | Jan 26, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phplinkdirectory.
Media articles that mention a CVE ID that affects a product developed by Phplinkdirectory — matched by CVE ID, not by vendor name.