Pozscripts develops a small suite of open-source web applications for classified ads, business directories, video sharing, and e-commerce, which are deployed across small-to-medium websites and community platforms. The vendor's vulnerability profile concentrates narrowly on SQL injection weaknesses across these applications, a classic input-validation flaw endemic to older PHP codebases that frequently attracts public exploit tooling. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pozscripts over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5496HIGH SQL injection vulnerability in showcategory.php in PozScripts Business Directory Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | Dec 12, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4755HIGH SQL injection vulnerability in gotourl.php in PozScripts Classified Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | Oct 28, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-3672HIGH SQL injection vulnerability in showcategory.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector tha | Aug 13, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-3673HIGH SQL injection vulnerability in browsecats.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than | Aug 13, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-3674HIGH SQL injection vulnerability in ugroups.php in PozScripts TubeGuru Video Sharing Script allows remote attackers to execute arbitrary SQL commands via the UID parameter. | Aug 13, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-3585HIGH Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) product_desc.p | Aug 11, 2008 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pozscripts.
Media articles that mention a CVE ID that affects a product developed by Pozscripts — matched by CVE ID, not by vendor name.