Tutos maintains a focused product line centered on its web-based platform, with a narrowly scoped vulnerability surface reflecting the application's role. The observed disclosures involve classification issues typical of early-stage vulnerability reporting; current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tutos over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0148HIGH TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request. | Jan 9, 2008 | 10.0 | 43 | NO | YES |
CVE-2004-2161HIGH SQL injection vulnerability in file_overview.php in TUTOS 1.1 allows remote attackers to execute arbitrary SQL commands via the link_id parameter. | Dec 31, 2004 | 7.5 | 29 | NO | YES |
CVE-2008-0149MEDIUM TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function. | Jan 9, 2008 | 5.0 | 27 | NO | YES |
CVE-2004-2162MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the search field of the Address Module or (2) | Dec 31, 2004 | 4.3 | 27 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tutos.
Media articles that mention a CVE ID that affects a product developed by Tutos — matched by CVE ID, not by vendor name.