Tuxplanet operates a focused blog platform product, Bilboblog, with a durable signal centered on web-application input-handling and data-exposure issues including cross-site scripting, SQL injection, and sensitive information disclosure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tuxplanet over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3303MEDIUM admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative access via a direct request that se | Jul 25, 2008 | 6.8 | 31 | NO | YES |
CVE-2008-3302MEDIUM SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote authenticated administrators to execute arbitrary SQL commands | Jul 25, 2008 | 6.0 | 25 | NO | YES |
CVE-2008-3304MEDIUM BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which re | Jul 25, 2008 | 5.0 | 24 | NO | YES |
Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) content paramete | Jul 25, 2008 | 3.5 | 20 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tuxplanet.
Media articles that mention a CVE ID that affects a product developed by Tuxplanet — matched by CVE ID, not by vendor name.