Quickersite is a website-building and site-management platform whose vulnerability profile centers on a single product affected by a persistent set of application-layer input-handling weaknesses. The recurring exposure spans code injection, cross-site scripting, SQL injection, and input-validation issues typical of web applications handling user-supplied content and database queries, and the vendor's disclosures have a strong tendency toward public exploit availability. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quickersite over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6677HIGH Unrestricted file upload vulnerability in fckeditor251/editor/filemanager/connectors/asp/upload.asp in QuickerSite 1.8.5 allows remote attackers to execute arbitrary code by upload | Apr 8, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6678HIGH SQL injection vulnerability in asp/includes/contact.asp in QuickerSite 1.8.5 allows remote attackers to execute arbitrary SQL commands via the sNickName parameter in a profile acti | Apr 8, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6673HIGH asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, which allows remote attackers to (1) change the admin password via the cSav | Apr 8, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6676MEDIUM QuickerSite 1.8.5 allows remote attackers to obtain sensitive information via a request to showThumb.aspx without any parameters, which reveals the installation path in an error me | Apr 8, 2009 | 5.0 | 23 | NO | YES |
CVE-2008-6674MEDIUM mailPage.asp in QuickerSite 1.8.5 allows remote attackers to flood e-mail accounts with messages via a large number of requests with a modified sEmail parameter. | Apr 8, 2009 | 5.0 | 23 | NO | YES |
CVE-2008-6675MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in QuickerSite 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the close parameter to showThumb.aspx | Apr 8, 2009 | 4.3 | 21 | NO | YES |
CVE-2007-3940MEDIUM Cross-site scripting (XSS) vulnerability in default.asp in QuickerSite 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the svalue parameter in a search act | Jul 21, 2007 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quickersite.
Media articles that mention a CVE ID that affects a product developed by Quickersite — matched by CVE ID, not by vendor name.