This page aggregates publicly disclosed CVE and security risk information related to web4future, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2006-2244 | Multiple SQL injection vulnerabilities in Web4Future News Portal allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) comentarii.php or (2) view.php. | [email protected] | 6.4 | 0.42% | 2006-05-09 | 2026-04-16 |
| CVE-2006-2243 | Multiple cross-site scripting (XSS) vulnerabilities in Web4Future News Portal allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) comentarii.php or (2) view.php. NOTE: this issue might be resultant from SQL injection. | [email protected] | 5.8 | 0.42% | 2006-05-09 | 2026-04-16 |
| CVE-2005-4039 | Directory traversal vulnerability in arhiva.php in Web4Future Portal Solutions News Portal allows remote attackers to read arbitrary files via the dir parameter. | [email protected] | 7.8 | 4.66% | 2005-12-06 | 2026-04-16 |
| CVE-2005-4038 | SQL injection vulnerability in comentarii.php in Web4Future Portal Solutions News Portal allows remote attackers to execute arbitrary SQL commands via the idp parameter. | [email protected] | 7.5 | 1.00% | 2005-12-06 | 2026-04-16 |
| CVE-2005-4036 | Cross-site scripting (XSS) vulnerability in index.cgi in Web4Future KeyWord Frequency Counter 1.0 allows remote attackers to inject arbitrary web script or HTML via the "remote URL." | [email protected] | 4.3 | 0.35% | 2005-12-06 | 2026-04-16 |
| CVE-2005-4034 | Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php. | [email protected] | 7.5 | 0.80% | 2005-12-06 | 2026-04-16 |