Kalptaru Infotech

    Dashboard / Vendors

    Products: 4
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    4
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2008-7076

    Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile photo, then accessing it via a direct request to the file in authorphoto/.

    Last Modified: Apr 23, 2026
    Published: Aug 25, 2009

    CVE-2008-7075

    Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles 6.0 allow remote attackers to inject arbitrary SQL commands via (1) the subcatid parameter to article.list.php; or the artid parameter to (2) article.print.php, (3) article.comments.php, (4) article.publisher.php, or (5) article.download.php; and (6) the PATH_INFO to article.download.php. NOTE: some of these details are obtained from third party information.

    Last Modified: Apr 23, 2026
    Published: Aug 25, 2009

    CVE-2008-5590

    SQL injection vulnerability in customer.forumtopic.php in Kalptaru Infotech Product Sale Framework 0.1 beta allows remote attackers to execute arbitrary SQL commands via the forum_topic_id parameter.

    Last Modified: Apr 23, 2026
    Published: Dec 16, 2008

    CVE-2008-2865

    SQL injection vulnerability in index.php in Kalptaru Infotech PHP Site Lock 2.0 allows remote attackers to execute arbitrary SQL commands via the articleid parameter in a show_article action.

    Last Modified: Apr 23, 2026
    Published: Jun 25, 2008

    CVE-2008-2791

    SQL injection vulnerability in product.detail.php in Kalptaru Infotech Comparison Engine Power Script 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Last Modified: Apr 23, 2026
    Published: Jun 20, 2008
    Items Per Page
    Kalptaru_Infotech Vulnerabilities & Security CVEs | CVE-DB