Vu maintains a narrow product portfolio focused on case management and mass mailing applications, with a durable vulnerability signal centered on SQL injection flaws in input handling. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vu over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6138HIGH SQL injection vulnerability in redir.asp in VU Mass Mailer allows remote attackers to execute arbitrary SQL commands via the password parameter to Default.asp (aka the Login Page). | Nov 27, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-6168HIGH SQL injection vulnerability in default.asp in VU Case Manager allows remote attackers to execute arbitrary SQL commands via the username parameter, a different vector than CVE-2007 | Nov 29, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-6143HIGH SQL injection vulnerability in default.asp (aka the Login Page) in VU Case Manager allows remote attackers to execute arbitrary SQL commands via the password parameter. | Nov 27, 2007 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vu.
Media articles that mention a CVE ID that affects a product developed by Vu — matched by CVE ID, not by vendor name.