Sips is a narrowly scoped vendor with a focused product line, where the durable signal centers on information-disclosure and data-exposure vulnerabilities affecting its payment-processing systems. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sips over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-2218HIGH CRLF injection vulnerability in the setUserValue function in sipssys/code/site.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) before 20020209 has unknown impa | Dec 31, 2002 | 10.0 | 30 | NO | NO |
CVE-2006-4733HIGH PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) 0.3.1 and earlier allows remote attackers to execut | Sep 13, 2006 | 7.5 | 29 | NO | YES |
CVE-2002-0267HIGH preferences.php in Simple Internet Publishing System (SIPS) before 0.3.1 allows remote attackers to gain administrative privileges via a linebreak in the "theme" field followed by | May 29, 2002 | 10.0 | 25 | NO | NO |
CVE-2000-1241HIGH Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 has an unknown impact and attack vectors, related to a "grave security fault." | Dec 31, 2000 | 10.0 | 24 | NO | NO |
CVE-2003-1553MEDIUM Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obta | Dec 31, 2003 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sips.
Media articles that mention a CVE ID that affects a product developed by Sips — matched by CVE ID, not by vendor name.