kalptaru_infotech CVE Vulnerabilities & CVE List (5)

Products (CPE): — CVEs: 5

kalptaru_infotech vulnerability overview

Aggregates CVE and security vulnerability intelligence across all kalptaru_infotech-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk sql injection, with potential vendor impact data exposure across vendor surface archive handling and vendor surface file processing use cases.

Vulnerability distribution trend (last 24 months)

Showing 15 of 5 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2008-7076 Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile photo, then accessing it via a direct request to the file in authorphoto/. [email protected] 6.5 3.39% 2009-08-25 2026-06-16
CVE-2008-7075 Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles 6.0 allow remote attackers to inject arbitrary SQL commands via (1) the subcatid parameter to article.list.php; or the artid parameter to (2) article.print.php, (3) article.comments.php, (4) article.publisher.php, or (5) article.download.php; and (6) the PATH_INFO to article.download.php. NOTE: some of these details are obtained from third party information. [email protected] 7.5 2.03% 2009-08-25 2026-06-16
CVE-2008-5590 SQL injection vulnerability in customer.forumtopic.php in Kalptaru Infotech Product Sale Framework 0.1 beta allows remote attackers to execute arbitrary SQL commands via the forum_topic_id parameter. [email protected] 7.5 0.97% 2008-12-16 2026-06-16
CVE-2008-2865 SQL injection vulnerability in index.php in Kalptaru Infotech PHP Site Lock 2.0 allows remote attackers to execute arbitrary SQL commands via the articleid parameter in a show_article action. [email protected] 7.5 0.97% 2008-06-25 2026-06-16
CVE-2008-2791 SQL injection vulnerability in product.detail.php in Kalptaru Infotech Comparison Engine Power Script 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. [email protected] 7.5 0.97% 2008-06-20 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence