Uploadscript develops file-upload and file-handling utilities with a narrow product footprint centered on upload and image-processing components. The identified vulnerability patterns are mapped to the NVD's general placeholder category, indicating that specific weakness characterization would benefit from detailed disclosure review; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uploadscript over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0246HIGH admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via | Jan 12, 2008 | 10.0 | 37 | NO | YES |
CVE-2008-0245HIGH admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via t | Jan 12, 2008 | 7.5 | 32 | NO | YES |
CVE-2006-6377HIGH Uploadscript 1.2 and earlier stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain the admin password hash via a direct | Dec 7, 2006 | 7.5 | 29 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uploadscript.
Media articles that mention a CVE ID that affects a product developed by Uploadscript — matched by CVE ID, not by vendor name.