Powie develops a small focused portfolio of web-based and server applications including forum, file-sharing, news, and system-management products that handle user input across multiple interfaces. Its vulnerability pattern centers on input-handling and injection flaws, particularly SQL injection and cross-site scripting, reflecting the exposure typical of dynamic web applications; these classes frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Powie over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6524HIGH SQL injection vulnerability in kommentar.php in pGB 2.12 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jan 31, 2013 | 7.5 | 31 | NO | YES |
CVE-2002-0319HIGH Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a user | Jun 25, 2002 | 7.5 | 31 | NO | YES |
CVE-2012-1210HIGH SQL injection vulnerability in pfile/file.php in Powie pFile 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Feb 24, 2012 | 7.5 | 30 | NO | YES |
CVE-2008-5269HIGH SQL injection vulnerability in index.php in pSys 0.7.0 alpha allows remote attackers to execute arbitrary SQL commands via the shownews parameter. | Nov 28, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4357HIGH SQL injection vulnerability in linkto.php in Powie pLink 2.07 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Sep 30, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4355HIGH SQL injection vulnerability in showprofil.php in Powie PSCRIPT Forum (aka PHP Forum or pForum) 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the id | Sep 30, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4347HIGH SQL injection vulnerability in newskom.php in Powie pNews 2.03 allows remote attackers to execute arbitrary SQL commands via the newsid parameter. | Sep 30, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-3131MEDIUM SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showid paramete | Jul 10, 2008 | 6.8 | 28 | NO | YES |
CVE-2008-2673HIGH SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the shownews | Jun 12, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-6038HIGH SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | Nov 22, 2006 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Powie.
Media articles that mention a CVE ID that affects a product developed by Powie — matched by CVE ID, not by vendor name.