Simplecustomer's vulnerability profile centers on a narrowly scoped customer management platform product where the durable signal reflects application-layer input-handling weaknesses, particularly SQL injection in command construction. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simplecustomer over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6332HIGH SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter. | Feb 27, 2009 | 7.5 | 33 | NO | YES |
CVE-2008-6326HIGH SQL injection vulnerability in login.php in Simple Customer as downloaded on 20081118 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the | Feb 27, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6081HIGH SQL injection vulnerability in contact.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Feb 6, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-1637MEDIUM profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address and password via the email and p | May 15, 2009 | 6.4 | 26 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simplecustomer.
Media articles that mention a CVE ID that affects a product developed by Simplecustomer — matched by CVE ID, not by vendor name.