softcomplex records
6 published records for vendor softcomplex.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-3684No exploit | PHP remote file inclusion vulnerability in calendar.php in SoftComplex PHP Event Calendar 1.4 allows remote attackers to execute arbitrary Psoftcomplex · php event calendar | High7.5 | — | 2.1% | Jul 21, 2006 |
30Monitor | CVE-2008-6485Proof of concept | SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary SQL commands via the softcomplex · php image gallery · CWE-89 | High7.5 | — | 1.0% | Mar 18, 2009 |
30Monitor | CVE-2008-6488Proof of concept | SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via softcomplex · php image gallery · CWE-89 | High7.5 | — | 1.0% | Mar 18, 2009 |
18Monitor | CVE-2006-4825Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in cl_files/index.php in SoftComplex PHP Event Calendar 1.5.1, and possibly earlier, allsoftcomplex · php event calendar | Medium4.3 | — | 4.0% | Sep 15, 2006 |
17Monitor | CVE-2008-2675No exploit | Cross-site scripting (XSS) vulnerability in index.php in PHP Image Gallery allows remote attackers to inject arbitrary web script or HTML visoftcomplex · php image gallery · CWE-79 | Medium4.3 | — | 1.0% | Jun 12, 2008 |
14Monitor | CVE-2006-0657No exploit | Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web scrsoftcomplex · php event calendar | Low3.5 | — | 1.1% | Feb 13, 2006 |
- CVE-2006-368431Monitor
PHP remote file inclusion vulnerability in calendar.php in SoftComplex PHP Event Calendar 1.4 allows remote attackers to execute arbitrary P
HighCVSS 7.5No exploitEPSS 2%softcomplex · php event calendarJul 21, 2006
- CVE-2008-648530Monitor
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5Proof of conceptEPSS 1%softcomplex · php image galleryMar 18, 2009
- CVE-2008-648830Monitor
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%softcomplex · php image galleryMar 18, 2009
- CVE-2006-482518Monitor
Multiple cross-site scripting (XSS) vulnerabilities in cl_files/index.php in SoftComplex PHP Event Calendar 1.5.1, and possibly earlier, all
MediumCVSS 4.3Proof of conceptEPSS 4%softcomplex · php event calendarSep 15, 2006
- CVE-2008-267517Monitor
Cross-site scripting (XSS) vulnerability in index.php in PHP Image Gallery allows remote attackers to inject arbitrary web script or HTML vi
MediumCVSS 4.3No exploitEPSS 1%softcomplex · php image galleryJun 12, 2008
- CVE-2006-065714Monitor
Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web scr
LowCVSS 3.5No exploitEPSS 1%softcomplex · php event calendarFeb 13, 2006