Phpscripte24 develops a series of web-based auction and social-commerce platforms, including pay-per-watch bidding systems, shopping portals, and community networking applications, that expose classic server-side web vulnerabilities. The vendor's disclosures center on application-layer input-handling flaws—SQL injection and cross-site scripting—that are endemic to dynamically generated web content and reflect the challenges of sanitizing user input across auction and social-interaction workflows. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpscripte24 over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1855HIGH SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arbitrary SQL commands via the id_auk parameter. | May 7, 2010 | 7.5 | 32 | NO | YES |
CVE-2010-1923HIGH SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id par | May 12, 2010 | 7.5 | 30 | NO | YES |
CVE-2010-1270HIGH SQL injection vulnerability in auktion.php in Multi Auktions Komplett System 2 allows remote attackers to execute arbitrary SQL commands via the id_auk parameter. | Apr 6, 2010 | 7.5 | 30 | NO | YES |
CVE-2010-1924HIGH SQL injection vulnerability in index.php in Hi Web Wiesbaden Live Shopping Multi Portal System allows remote attackers to execute arbitrary SQL commands via the artikel parameter. | May 12, 2010 | 7.5 | 29 | NO | YES |
CVE-2010-1269HIGH SQL injection vulnerability in auktion.php in phpscripte24 Niedrig Gebote Pro Auktions System II allows remote attackers to execute arbitrary SQL commands via the id_auk parameter. | Apr 6, 2010 | 7.5 | 28 | NO | YES |
CVE-2010-1854MEDIUM Cross-site scripting (XSS) vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to inject arbitrary web script or HTML via the id_auk paramet | May 7, 2010 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpscripte24.
Media articles that mention a CVE ID that affects a product developed by Phpscripte24 — matched by CVE ID, not by vendor name.