Phppgads is a niche PHP-based advertising and ad-management platform whose vulnerability footprint concentrates in input-handling weaknesses characteristic of web applications, particularly SQL injection and sensitive-information disclosure. The recurring exposure pattern reflects the product's direct interaction with user-supplied data and database queries, areas where defensive coding practices in legacy web frameworks are often incomplete. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phppgads over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2636HIGH SQL injection vulnerability in lib-view-direct.inc.php in phpAdsNew and phpPgAds before 2.0.6 allows remote attackers to execute arbitrary SQL commands via the clientid parameter. | Aug 23, 2005 | 7.5 | 22 | NO | NO |
CVE-2005-3646HIGH Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote attackers to execute arbitrary SQL command | Nov 17, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-3791MEDIUM HTTP response splitting vulnerability in phpAdsNew and phpPgAds 2.0.6 and earlier allows remote attackers to inject arbitrary HTML headers via adclick.php and possibly other unspec | Nov 24, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-3645MEDIUM phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allows remote attackers to obtain the application installation path and other sensitive information via direct requests t | Nov 17, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-2635MEDIUM Multiple directory traversal vulnerabilities in phpAdsNew and phpPgAds before 2.0.6 allow remote attackers to include arbitrary files via a .. (dot dot) in the (1) layerstyle param | Aug 23, 2005 | 5.0 | 15 | NO | NO |
CVE-2006-5515MEDIUM Cross-site scripting (XSS) vulnerability in lib-history.inc.php in phpAdsNew and phpPgAds before 2.0.8-pr1 allows remote attackers to inject arbitrary web script or HTML via unspec | Oct 26, 2006 | 4.3 | 14 | NO | NO |
CVE-2006-1397MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in (a) phpAdsNew and (b) phpPgAds before 2.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) certain | Mar 28, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phppgads.
Media articles that mention a CVE ID that affects a product developed by Phppgads — matched by CVE ID, not by vendor name.