Raven Php Scripts maintains a narrowly scoped portfolio centered around the Keep It Simple Guest Book application, a web-based PHP component. The observed vulnerability exposure centers on path-traversal weaknesses, a characteristic flaw class in web scripts that handle file access without sufficient directory restriction. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Raven Php Scripts over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1635HIGH Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and execute arbitrary local files vi | Apr 2, 2008 | 7.5 | 34 | NO | YES |
CVE-2009-0677MEDIUM avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP seq | Feb 22, 2009 | 6.5 | 29 | NO | YES |
CVE-2009-0673MEDIUM Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to execute arbi | Feb 22, 2009 | 6.5 | 26 | NO | YES |
CVE-2009-0672MEDIUM SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to execute arbitrary SQL commands via the use | Feb 22, 2009 | 6.5 | 26 | NO | YES |
CVE-2009-0674MEDIUM images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows remote attackers to determine the existence of local files by | Feb 22, 2009 | 6.0 | 25 | NO | YES |
CVE-2009-0678MEDIUM images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array parameter value that does not correspond to a valid font file, whic | Feb 22, 2009 | 5.0 | 23 | NO | YES |
CVE-2009-0679MEDIUM Cross-site scripting (XSS) vulnerability in the Your Account module in RavenNuke 2.30 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Feb 22, 2009 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Raven Php Scripts.
Media articles that mention a CVE ID that affects a product developed by Raven Php Scripts — matched by CVE ID, not by vendor name.