Sandbox maintains a focused vulnerability profile centered on a product bearing the same name, with the observed exposure pattern reflecting code-injection risks and classification gaps typical of emerging or narrowly scoped tools. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sandbox over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5694HIGH PHP remote file inclusion vulnerability in lib/jpgraph/jpgraph_errhandler.inc.php in Sandbox 1.4.1 might allow remote attackers to execute arbitrary PHP code via unspecified vector | Dec 19, 2008 | 10.0 | 25 | NO | NO |
Race condition in sandbox before 1.2.11 allows local users to create or overwrite arbitrary files via symlink attack on sandboxpids.tmp. | Aug 3, 2005 | 1.2 | 11 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sandbox.
Media articles that mention a CVE ID that affects a product developed by Sandbox — matched by CVE ID, not by vendor name.