Thinkfactory maintains a focused product line centered on enterprise resource management and e-commerce platforms, including its Ultimate Estate, ThinkWMS, Ultimate eShop, and UltimateGoogle offerings. The observed vulnerability reports reflect the vendor's positioning in back-office and web-facing business software, with weakness classifications that span general categorization schemes. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thinkfactory over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3236HIGH Multiple SQL injection vulnerabilities in thinkWMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) index.php or (b) printar | Jun 27, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-3154HIGH SQL injection vulnerability in index.pl in Ultimate Estate 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jun 22, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-3157MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Thinkfactory UltimateGoogle 1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ par | Jun 22, 2006 | 5.8 | 16 | NO | NO |
CVE-2006-3153MEDIUM Cross-site scripting (XSS) vulnerability in index.pl in Ultimate Estate 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | Jun 22, 2006 | 4.3 | 14 | NO | NO |
CVE-2006-3155MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in | Jun 22, 2006 | 4.3 | 14 | NO | NO |
CVE-2006-3156MEDIUM Cross-site scripting (XSS) vulnerability in index.cgi in Ultimate eShop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the subid parameter. | Jun 22, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thinkfactory.
Media articles that mention a CVE ID that affects a product developed by Thinkfactory — matched by CVE ID, not by vendor name.