Prozilla's vulnerability profile centers on a modest portfolio of web-facing applications and utilities, including a download accelerator, hosting and directory scripts, and forum software, which collectively present a typical attack surface for application-tier deployment. The recurring exposure pattern is rooted in input-handling weaknesses, particularly SQL injection and improper input validation, that are characteristic of web applications where user-supplied data flows into backend queries and processing logic. Vulnerabilities affecting this vendor have a strong tendency to acquire public exploit code, reflecting both the accessibility of web-application attack vectors and the open-source or widely inspected nature of the products. Live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Prozilla over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1120HIGH Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier allow remote servers to execute | Jan 10, 2005 | 10.0 | 42 | NO | YES |
CVE-2005-2961HIGH Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option enabled, allows remote servers to execute arbitrary code via | Oct 5, 2005 | 7.5 | 32 | NO | YES |
CVE-2005-0523HIGH Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Location header. | May 2, 2005 | 7.5 | 32 | NO | YES |
CVE-2008-1784HIGH Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3) uidx.php in siteadmin/. | Apr 15, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-6115HIGH SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL commands via the id parameter in a deadlink action, a differ | Feb 11, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-1863HIGH SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Apr 17, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-1864HIGH SQL injection vulnerability in project.php in Prozilla Freelancers allows remote attackers to execute arbitrary SQL commands via the project parameter. | Apr 17, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-1788HIGH SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: some o | Apr 15, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-4258HIGH SQL injection vulnerability in directory.php in Prozilla Pub Site Directory allows remote attackers to execute arbitrary SQL commands via the cat parameter. | Aug 8, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-3809HIGH Multiple SQL injection vulnerabilities in Prozilla Directory Script allow remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action to directory. | Jul 17, 2007 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Prozilla.
Media articles that mention a CVE ID that affects a product developed by Prozilla — matched by CVE ID, not by vendor name.