Scriptsfeed develops a line of web-based directory and portal applications—including recipe listings, script directories, classified ads, and dating software—that are built on PHP or similar server-side scripting stacks. Its vulnerability profile is characterized by recurring input-validation and SQL-injection weaknesses endemic to server-side web applications, and these disclosures have a strong tendency to acquire public exploit code. Live severity, exploitation activity, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scriptsfeed over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-5039HIGH SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter | Nov 2, 2011 | 7.5 | 31 | NO | YES |
CVE-2010-2906HIGH SQL injection vulnerability in articlesdetails.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id par | Jul 28, 2010 | 7.5 | 31 | NO | YES |
CVE-2010-2905HIGH SQL injection vulnerability in info.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jul 28, 2010 | 7.5 | 31 | NO | YES |
CVE-2010-1092HIGH Multiple SQL injection vulnerabilities in login.php in ScriptsFeed Business Directory Software allow remote attackers to execute arbitrary SQL commands via the (1) us and (2) ps pa | Mar 24, 2010 | 7.5 | 28 | NO | YES |
CVE-2008-6944MEDIUM Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension | Aug 12, 2009 | 6.5 | 27 | NO | YES |
CVE-2008-6943MEDIUM Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable exte | Aug 12, 2009 | 6.5 | 27 | NO | YES |
CVE-2008-6942MEDIUM Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows remote authenticated users to execute arbitrary code by upload | Aug 12, 2009 | 6.5 | 27 | NO | YES |
CVE-2010-1096HIGH Multiple SQL injection vulnerabilities in searchmatch.php in ScriptsFeed Dating Software allow remote attackers to execute arbitrary SQL commands via the (1) txtgender and (2) txtl | Mar 24, 2010 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scriptsfeed.
Media articles that mention a CVE ID that affects a product developed by Scriptsfeed — matched by CVE ID, not by vendor name.