Aggregates CVE and security vulnerability intelligence across all netart_media-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk sql injection and related security problems, affecting vendor surface file processing, vendor surface automated decompression, and vendor surface archive handling scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2008-6111 | SQL injection vulnerability in blog.php in NetArt Media Vlog System 1.1 allows remote attackers to execute arbitrary SQL commands via the note parameter. | [email protected] | 7.5 | 0.52% | 2009-02-11 | 2026-04-23 |
| CVE-2008-5311 | SQL injection vulnerability in image.php in NetArt Media Blog System 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | [email protected] | 7.5 | 0.42% | 2008-12-02 | 2026-04-23 |
| CVE-2008-5310 | SQL injection vulnerability in image.php in NetArt Media Car Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | [email protected] | 7.5 | 0.71% | 2008-12-02 | 2026-04-23 |
| CVE-2008-5309 | SQL injection vulnerability in NetArt Media Real Estate Portal 1.2 allows remote attackers to execute arbitrary SQL commands via the ad_id parameter in the re_send_email module to index.php. | [email protected] | 7.5 | 0.41% | 2008-12-02 | 2026-04-23 |
| CVE-2007-3979 | SQL injection vulnerability in index.php in BlogSite Professional (aka Blog System) 1.x allows remote attackers to execute arbitrary SQL commands via the news_id parameter. | [email protected] | 6.8 | 1.21% | 2007-07-25 | 2026-04-23 |
| CVE-2007-3434 | index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the page parameter, which reveals the table prefix in an error message. | [email protected] | 5.0 | 6.19% | 2007-06-27 | 2026-04-23 |
| CVE-2007-3433 | SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action. | [email protected] | 7.5 | 0.71% | 2007-06-27 | 2026-04-23 |
| CVE-2005-4049 | Multiple SQL injection vulnerabilities in Blog System 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the cat parameter in index.php and (2) the note parameter in blog.php. | [email protected] | 7.5 | 2.18% | 2005-12-07 | 2026-04-16 |