Xqus maintains a small suite of news and statistics products (including X-News and X-Stat) that have attracted security disclosures centered on unclassified or placeholder weakness categories. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xqus over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1656HIGH X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or the users.txt data file, and pro | Dec 31, 2002 | 7.5 | 31 | NO | YES |
CVE-2002-2046HIGH x_news.php in X-News (x_news) 1.1 and earlier allows remote attackers to gain administrative privileges by stealing and replaying the md5_password cookie. | Dec 31, 2002 | 7.5 | 19 | NO | NO |
CVE-2002-2044MEDIUM Cross-site scripting (XSS) vulnerability in x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the phpinfo | Dec 31, 2002 | 4.3 | 18 | NO | NO |
CVE-2002-2045MEDIUM x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to (1) execute PHP commands such as phpinfo or (2) obtain the full path of the web server via an invalid action p | Dec 31, 2002 | 6.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xqus.
Media articles that mention a CVE ID that affects a product developed by Xqus — matched by CVE ID, not by vendor name.