Sisfo Kampus is a niche educational-management platform focused on campus administrative functions, with a concentrated product footprint and a specific vulnerability profile centered on path-traversal weaknesses and directory-access controls. The vendor's disclosures frequently acquire public exploit tooling, reflecting the accessibility of input-validation flaws in web-based administrative interfaces. Defenders deploying this platform should prioritize patches addressing path-traversal exposure and restrict network access to administrative functions; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sisfo Kampus over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4820HIGH Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitrary local files, and possibly execute local PHP scripts, via | Sep 11, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-6137HIGH Multiple PHP remote file inclusion vulnerabilities in Sisfo Kampus 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the (1) exec parameter to index.php or (2) | Nov 28, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6140HIGH PHP remote file inclusion vulnerability in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to execute arbitrary PHP code via a URL in the slnt parameter to (1) index.php and | Nov 28, 2006 | 7.5 | 28 | NO | YES |
CVE-2007-4895MEDIUM Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the f parameter. | Sep 14, 2007 | 5.0 | 23 | NO | YES |
CVE-2006-6138MEDIUM Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname in the dir parameter. | Nov 28, 2006 | 5.0 | 23 | NO | YES |
CVE-2006-6139MEDIUM Directory traversal vulnerability in downloadexcel.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the fn parameter. NOTE: the provenance | Nov 28, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sisfo Kampus.
Media articles that mention a CVE ID that affects a product developed by Sisfo Kampus — matched by CVE ID, not by vendor name.