Phpsurveyor is a web-based survey and questionnaire application whose reported vulnerabilities center on its core product. The durable signal from its disclosures involves input-handling and web-application weaknesses, which are typical of self-hosted PHP survey tools; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpsurveyor over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2065HIGH SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie. NOTE: this issue could | Apr 27, 2006 | 7.5 | 28 | NO | YES |
CVE-2005-2398HIGH Multiple SQL injection vulnerabilities in PHP Surveyor 0.98 allows remote attackers to execute arbitrary SQL commands via (1) the sid, start, and id parameters to browse.php, the s | Jul 27, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-4586HIGH Multiple SQL injection vulnerabilities in PHPSurveyor before 0.991 allow remote attackers to execute arbitrary SQL commands via the (1) sql parameter in browse.php and the (2) sid, | Dec 30, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-2399HIGH PHP Surveyor 0.98 allows remote attackers to trigger SQL errors via missing parameters to (1) browse.php, (2) export.php, (3) conditions.php, or (4) spss.php. | Jul 27, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-2380MEDIUM Multiple cross-site scripting vulnerabilities in PHP Surveyor 0.98 allow remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) start, and (3) id parameters t | Jul 26, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-2381MEDIUM PHP Surveyor 0.98 allows remote attackers to obtain sensitive information via a direct request to (1) question.php, (2) survey.php, or (3) group.php in the root directory, a direct | Jul 26, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpsurveyor.
Media articles that mention a CVE ID that affects a product developed by Phpsurveyor — matched by CVE ID, not by vendor name.