Known Vulnerabilities for products from Hinton Design

Listed below are 16 of the newest known vulnerabilities associated with the vendor "Hinton Design".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2007-2096 json PHP remote file inclusion vulnerability in common.php in Hinton Design PHPHD Download System (phphd_downloads) allows remote ... Not Provided 2007-04-18 2026-04-23
CVE-2006-7091 json PHP remote file inclusion vulnerability in config.php in phpht Topsites FREE 1.022b allows remote attackers to execute arbitr... Not Provided 2007-03-02 2026-04-23
CVE-2006-5460 json Multiple PHP remote file inclusion vulnerabilities in Hinton Design phpht Topsites allow remote attackers to execute arbitrar... Not Provided 2006-10-23 2026-04-23
CVE-2006-5458 json PHP remote file inclusion vulnerability in common.php in Hinton Design phpht Topsites allows remote attackers to execute arbi... Not Provided 2006-10-23 2026-04-23
CVE-2006-0655 json Multiple cross-site scripting (XSS) vulnerabilities in (1) link_edited.php and (2) link_added.php in Hinton Design phpht Tops... Not Provided 2006-02-13 2025-04-03
CVE-2006-0654 json check.php in Hinton Design phpht Topsites 1.3 does not validate passwords when using cookies, which allows remote attackers t... Not Provided 2006-02-13 2025-04-03
CVE-2006-0653 json Multiple SQL injection vulnerabilities in Hinton Design phpht Topsites 1.3 allow remote attackers to execute arbitrary SQL co... Not Provided 2006-02-13 2025-04-03
CVE-2006-0609 json Cross-site scripting (XSS) vulnerability in add.php in Hinton Design phphd 1.0 allows remote attackers to inject arbitrary we... Not Provided 2006-02-08 2025-04-03
CVE-2006-0608 json Multiple SQL injection vulnerabilities in Hinton Design phphd 1.0 allow remote attackers to execute arbitrary SQL commands vi... Not Provided 2006-02-08 2025-04-03
CVE-2006-0607 json check.php in Hinton Design phphd 1.0 does not check passwords when certain cookies are provided, which allows remote attacker... Not Provided 2006-02-08 2025-04-03
CVE-2006-0604 json check.php in Hinton Design phphg Guestbook 1.2 does not check the user password when authenticating via cookies, which allows... Not Provided 2006-02-08 2025-04-03
CVE-2006-0603 json Multiple cross-site scripting vulnerabilities in signed.php in Hinton Design phphg Guestbook 1.2 allow remote attackers to in... Not Provided 2006-02-08 2025-04-03
CVE-2006-0602 json Multiple SQL injection vulnerabilities in Hinton Design phphg Guestbook 1.2 allow remote attackers to execute arbitrary SQL c... Not Provided 2006-02-08 2025-04-03
CVE-2006-0572 json phpstatus 1.0 does not require passwords when using cookies to identify a user, which allows remote attackers to bypass authe... Not Provided 2006-02-07 2025-04-03
CVE-2006-0571 json Multiple cross-site scripting (XSS) vulnerabilities in phpstatus 1.0 allow remote attackers to inject arbitrary web script or... Not Provided 2006-02-07 2025-04-03
CVE-2006-0570 json Multiple SQL injection vulnerabilities in phpstatus 1.0, when gpc_magic_quotes is disabled, allow remote attackers to execute... Not Provided 2006-02-07 2025-04-03

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report