This page aggregates publicly disclosed CVE and security risk information related to bizdesign, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2002-1867 | The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption). | [email protected] | 7.5 | 1.53% | 2002-12-31 | 2026-06-16 |
| CVE-2002-1801 | ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexistent image category, which leaks the web root in the resulting error message. | [email protected] | 5.0 | 1.53% | 2002-12-31 | 2026-06-16 |
| CVE-2002-1334 | Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi. | [email protected] | 6.8 | 4.69% | 2002-12-11 | 2026-06-16 |