Xlinesoft maintains a focused portfolio of web application development tools, primarily the ASPRunner and PHPRunner code-generation platforms, which despite modest disclosure volume occupy a disproportionately visible role in the vulnerability landscape. The recurring weakness classes affecting these products—SQL injection, cleartext storage of sensitive information, and related input-handling flaws—reflect the challenges of auto-generated application code and server-side template handling. Vulnerabilities in this vendor's products frequently acquire public exploit code; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xlinesoft over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0964HIGH UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged wit | Mar 19, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-0963HIGH Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserVie | Mar 19, 2009 | 7.5 | 28 | NO | YES |
CVE-2004-2059MEDIUM Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search. | Dec 31, 2004 | 5.0 | 26 | NO | YES |
CVE-2004-2060MEDIUM ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, whi | Dec 31, 2004 | 5.0 | 25 | NO | YES |
CVE-2004-2057HIGH SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements. | Dec 31, 2004 | 7.5 | 21 | NO | NO |
CVE-2004-2058MEDIUM ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages. | Dec 31, 2004 | 5.0 | 19 | NO | NO |
XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users t | Nov 17, 2006 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xlinesoft.
Media articles that mention a CVE ID that affects a product developed by Xlinesoft — matched by CVE ID, not by vendor name.