Refbase is a modestly represented open-source bibliographic reference management application that sits prominently among academic and research institutions. Its vulnerability profile clusters around web application input-handling and code-injection risks, with recurring issues in cross-site scripting, SQL injection, CSRF, and code-injection weaknesses that are characteristic of server-side web frameworks handling untrusted user input and database queries. The vendor's disclosures have frequently acquired public exploit code, reflecting the accessibility of web-facing instances and the relative ease of weaponizing these classes of flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Refbase over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-6008HIGH install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassword parameter, a different issue than CVE- | Sep 28, 2015 | 7.5 | 30 | NO | YES |
CVE-2015-7381HIGH Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary PHP code via the | Sep 28, 2015 | 7.5 | 29 | NO | YES |
CVE-2015-7382HIGH SQL injection vulnerability in install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary SQL commands via the defaultCharacterS | Sep 28, 2015 | 7.5 | 28 | NO | YES |
CVE-2015-6009HIGH Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands via (1) the where parameter to | Sep 28, 2015 | 7.5 | 28 | NO | YES |
CVE-2015-6007MEDIUM Cross-site request forgery (CSRF) vulnerability in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to hijack the authentication of arbitrary users. | Sep 28, 2015 | 6.8 | 18 | NO | NO |
CVE-2015-6012MEDIUM Multiple open redirect vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allow remote attackers to redirect users to arbitra | Sep 28, 2015 | 5.8 | 16 | NO | NO |
CVE-2015-6011MEDIUM Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allows remote attackers to conduct XML injection attacks via (1) the id parameter to unapi.ph | Sep 28, 2015 | 5.0 | 15 | NO | NO |
CVE-2015-7383MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge through 2015-04-28 allow remote attackers to inject arbi | Sep 28, 2015 | 4.3 | 14 | NO | NO |
CVE-2015-6010MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allow remote attackers to inject arbit | Sep 28, 2015 | 4.3 | 14 | NO | NO |
CVE-2008-6400MEDIUM Cross-site scripting (XSS) vulnerability in refbase before 0.9.5 allows remote attackers to inject arbitrary web script or HTML via the headerMsg parameter to (1) show.php and (2) | Mar 5, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Refbase.
Media articles that mention a CVE ID that affects a product developed by Refbase — matched by CVE ID, not by vendor name.