Upoint develops event publishing and file storage products that handle structured data and file operations, with its vulnerability exposure centered on application-layer input handling. The recurring weakness class of SQL injection reflects the risks inherent to database-backed file and event management systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Upoint over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-1278MEDIUM SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the | Mar 19, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-1277MEDIUM Cross-site scripting (XSS) vulnerability in signup.php in @1 File Store 2006.03.07 allows remote attackers to inject arbitrary web script or HTML via the (1) real_name, (2) email, | Mar 19, 2006 | 5.8 | 16 | NO | NO |
CVE-2006-1437MEDIUM UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a di | Apr 15, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-1436MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HTML via the (1) Event, (2) Description, ( | Apr 15, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Upoint.
Media articles that mention a CVE ID that affects a product developed by Upoint — matched by CVE ID, not by vendor name.