Scriptphp operates a focused line of web-based content-management and publishing applications, including announcement scripts, news portals, and image galleries, that present a narrow but concentrated attack surface. The vendor's vulnerability profile centers on application-layer input-handling weaknesses, principally cross-site scripting flaws, reflecting the web-facing and user-input-dependent nature of these products. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scriptphp over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6478HIGH Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) email.php, the (2) no paramet | Dec 12, 2006 | 7.5 | 32 | NO | YES |
CVE-2006-6519HIGH SQL injection vulnerability in lire-avis.php in ProNews 1.5 allows remote attackers to execute arbitrary SQL commands via the aa parameter. | Dec 14, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6521HIGH SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0 allows remote attackers to execute arbitrary SQL commands via the aa parameter. | Dec 14, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6520MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo parameter to (a) exis | Dec 14, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-6479MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the email parameter in (1) erreurinscri | Dec 12, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-6518MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ProNews 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo, (2) email, (3) date, (4) sujet, | Dec 14, 2006 | 6.8 | 26 | NO | YES |
CVE-2006-6580MEDIUM admin/change.php in ProNews 1.5 does not check whether a user is permitted to change news items, which allows remote attackers to add or delete information within an item, and poss | Dec 15, 2006 | 6.4 | 17 | NO | NO |
CVE-2008-2280MEDIUM Cross-site scripting (XSS) vulnerability in admin/index.php in Script PHP PicEngine 1.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter. NOTE: t | May 16, 2008 | 4.3 | 15 | NO | NO |
CVE-2006-6480MEDIUM admin/admin_membre/fiche_membre.php in AnnonceScriptHP 2.0 allows remote attackers to obtain sensitive information via the idmembre parameter, which discloses the passwords for arb | Dec 12, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scriptphp.
Media articles that mention a CVE ID that affects a product developed by Scriptphp — matched by CVE ID, not by vendor name.