X Scripts maintains a narrow portfolio centered on polling and statistics-collection utilities that, despite modest disclosure volume, serve specialized administrative and monitoring functions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by X Scripts over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3959HIGH SQL injection vulnerability in protect.php in X-Scripts X-Protection 1.10, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) use | Aug 1, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-3960HIGH SQL injection vulnerability in top.php in X-Scripts X-Poll, probably 2.30, allows remote attackers to execute arbitrary SQL commands via the poll parameter. NOTE: the provenance o | Aug 1, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-2281HIGH X-Scripts X-Poll (xpoll) 2.30 allows remote attackers to execute arbitrary PHP code by using admin/images/add.php to upload a PHP file, then access it. | May 10, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-3950HIGH SQL injection vulnerability in x-statistics.php in X-Scripts X-Statistics 1.20 allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header. | Aug 1, 2006 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by X Scripts.
Media articles that mention a CVE ID that affects a product developed by X Scripts — matched by CVE ID, not by vendor name.