Aggregates CVE and security vulnerability intelligence across all bpowerhouse-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Disclosed issues often relate to vendor risk sql injection and vendor risk path handling; exposure may include vendor impact data exposure and vendor impact file overwrite in vendor surface software deployment contexts.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2009-4540 | SQL injection vulnerability in page.php in Mini CMS 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | [email protected] | 6.8 | 0.29% | 2010-01-04 | 2026-04-23 |
| CVE-2009-3503 | Multiple SQL injection vulnerabilities in search.aspx in BPowerHouse BPHolidayLettings 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) rid and (2) tid parameters. | [email protected] | 7.5 | 0.34% | 2009-09-30 | 2026-04-23 |
| CVE-2009-3502 | SQL injection vulnerability in music.php in BPowerHouse BPMusic 1.0 allows remote attackers to execute arbitrary SQL commands via the music_id parameter. | [email protected] | 7.5 | 0.34% | 2009-09-30 | 2026-04-23 |
| CVE-2009-3501 | SQL injection vulnerability in students.php in BPowerHouse BPStudents 1.0 allows remote attackers to execute arbitrary SQL commands via the test parameter in a preview action. | [email protected] | 7.5 | 0.46% | 2009-09-30 | 2026-04-23 |
| CVE-2009-3500 | Multiple SQL injection vulnerabilities in BPowerHouse BPGames 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to main.php and (2) game_id parameter to game.php. | [email protected] | 7.5 | 0.34% | 2009-09-30 | 2026-04-23 |
| CVE-2009-3499 | SQL injection vulnerability in employee.aspx in BPowerHouse BPLawyerCaseDocuments 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | [email protected] | 7.5 | 0.32% | 2009-09-30 | 2026-04-23 |
| CVE-2008-5594 | Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin parameters. | [email protected] | 7.5 | 3.89% | 2008-12-16 | 2026-04-23 |
| CVE-2008-5593 | Multiple directory traversal vulnerabilities in index.php in Mini CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin parameters. | [email protected] | 7.5 | 3.83% | 2008-12-16 | 2026-04-23 |