Time from Exploit Publish Date to Vendor Solution Date

This page presents a list of vulnerabilities with the longest "time of exposure". This is calculated by looking at the exploit publication date and the vendor solution date. During this period, consumers may be vulnerable to the issue while public exploit code exists, allowing for easier and more widespread attacks.

Key 270+ Days 180-269 Days 0-179 Days

<< Back to Browse

ID Disc Date Days of Exposure Title
73824 2011-07-13 657437 days TCExam /admin/code/tce_edit_backup.php backup_file Parameter XSS
15631 2005-03-31 12873 days PHP Multiple Unspecified Issues
49736 2003-04-25 2027 days Microsoft Windows SMB NTLM Authentication Credential Replay Remote Code Execution
59037 2002-12-01 2016 days Thatware auth.inc.php user Parameter SQL Injection
14987 2004-03-26 1537 days XMB Forum post.php Multiple Parameter XSS
33567 2004-06-17 1423 days XMB U2U Instant Messenger memcp.php recipient Field XSS
36802 2007-06-04 1057 days Madirish Webmail lib/addressbook.php GLOBALS[basedir] Parameter Remote File Inclusion
12368 2004-12-09 942 days UseModWiki wiki.pl XSS
33130 2007-02-08 922 days HP Network Node Manager (NNM) Remote Console Directory Permission Weakness Privilege Escalation
24631 2006-04-09 762 days XMB Forum .swf Actionscript Execution
14238 2005-02-25 758 days BadBlue ext.dll mfcisapicommand Parameter Remote Overflow
15537 2005-04-18 727 days PayProCart usrauthstamp.php IP Disclosure
24166 2006-03-27 622 days phpmyfamily track.php name Parameter XSS
24167 2006-03-27 622 days phpmyfamily index.php PHPSESSID CRLF Injection Path Disclosure
42186 2008-02-14 582 days PHP Live! admin/traffic/knowledge_searchm.php questid Parameter SQL Injection
42559 2008-02-28 473 days Podcast Generator loadparser.php absoluteurl Parameter Remote File Inclusion
42560 2008-02-28 473 days Podcast Generator admin.php absoluteurl Parameter Remote File Inclusion
42562 2008-02-28 473 days Podcast Generator categories_add.php absoluteurl Parameter Remote File Inclusion
42563 2008-02-28 473 days Podcast Generator categories_remove.php absoluteurl Parameter Remote File Inclusion
42564 2008-02-28 473 days Podcast Generator edit.php absoluteurl Parameter Remote File Inclusion
42565 2008-02-28 473 days Podcast Generator editdel.php absoluteurl Parameter Remote File Inclusion
42566 2008-02-28 473 days Podcast Generator ftpfeature.php absoluteurl Parameter Remote File Inclusion
42567 2008-02-28 473 days Podcast Generator login.php absoluteurl Parameter Remote File Inclusion
42568 2008-02-28 473 days Podcast Generator pgRSSnews.php absoluteurl Parameter Remote File Inclusion
42569 2008-02-28 473 days Podcast Generator showcat.php absoluteurl Parameter Remote File Inclusion
42570 2008-02-28 473 days Podcast Generator upload.php absoluteurl Parameter Remote File Inclusion
42571 2008-02-28 473 days Podcast Generator archive_cat.php absoluteurl Parameter Remote File Inclusion
42572 2008-02-28 473 days Podcast Generator archive_nocat.php absoluteurl Parameter Remote File Inclusion
42573 2008-02-28 473 days Podcast Generator recent_list.php absoluteurl Parameter Remote File Inclusion
25073 2006-04-28 434 days Microsoft IE mhtml: Redirection Domain Restriction Bypass
32693 2007-01-17 390 days Apple Mac OS X Minimal SLP v2 Service Agent (slpd) Registration Request Overflow
41199 2007-12-14 368 days Drake CMS index.php option Parameter XSS
41494 2008-02-07 365 days Adobe Reader / Acrobat EScript.api Plug-in Crafted PDF Arbitrary Code Execution
64540 2010-03-23 359 days SAP GUI SAPBExCommonResources.BExGlobal ActiveX Arbitrary Command Execution
49325 2008-10-13 357 days Oracle Database Workspace Manager SYS.LT.MERGEWORKSPACE SQL Injection
14993 2005-03-21 345 days XMB Profile Mood Variables XSS
21488 2005-12-01 320 days Interspire FastFind index.php query Parameter XSS
30214 2006-11-06 296 days Microsoft Windows GDI Kernel Structure Modification Code Execution
53333 2009-03-23 295 days Apple Mac OS X XNU User Space Interaction Restriction Weakness Local Privilege Escalation
60586 2009-12-01 292 days phpMyFAQ index.php Multiple Parameter XSS
59001 2009-03-20 290 days Apache Axis2 xsd Parameter Traversal Arbitrary File Disclosure
23899 2006-03-14 289 days Microsoft Office Excel BIFF File Processing Malformed BOOLERR Record Arbitrary Code Execution
35128 2007-03-11 270 days AssetMan download_pdf.php pdf_file Parameter Traversal Arbitrary File Access
15465 2005-04-12 236 days Microsoft IE DHTML Object Memory Corruption Code Execution
72406 2011-05-18 224 days Opera Frameset Construct Handling Memory Corruption
64918 2009-09-25 224 days html2ps SSI include Directive Traversal Arbitrary File Access
71190 2011-02-23 222 days Local Market Explorer Plugin for WordPress wp-content/plugins/local-market-explorer/modules/walk-score-iframe.php api-key Parameter XSS
56531 2009-01-13 211 days Premier Election Solutions (Diebold) Global Election Management System (GEMS) Clear Button Audit Log Deletion
66388 2010-07-15 206 days XMB Admin Password Manipulation CSRF
58941 2008-12-17 183 days BIRT birt-viewer/run __report Parameter XSS
73474 2011-05-12 181 days GEAR CD DVD Filter Driver GEARAspiWDM.sys Pointers Table Invalid Memory Access Local DoS
73475 2011-05-12 181 days GEAR CD DVD Filter Driver GEARAspiWDM.sys Pointers Table Array Indexing Error Invalid Memory Access Local DoS
40694 2007-12-10 170 days Apple Mac OS X xnu Kernel bsd/kern/ubc_subr.c cs_validate_page() Function Local DoS
5252 2004-04-13 164 days Microsoft Windows Metafile Code Execution
27150 2006-07-11 149 days Microsoft Office MSO.DLL String Processing Overflow
58655 2007-03-20 148 days EZPhotoSales Default admin Account
67548 2010-08-25 139 days Microsoft Vista BitLocker Drive Encryption Path Subversion Arbitrary DLL Injection Code Execution
71840 2011-03-01 137 days Mingle Forum Plugin for WordPress wp-content/plugins/mingle-forum/wpf-insert.php message Parameter XSS
844 2001-07-02 134 days Apache Tomcat Java Servlet Error Page XSS
61229 2009-12-19 125 days Saurus CMS classes/excel/class.writeexcel_workbook.inc.php class_path Parameter Remote File Inclusion
61230 2009-12-19 125 days Saurus CMS classes/excel/class.writeexcel_worksheet.inc.php class_path Parameter Remote File Inclusion
47475 2008-08-13 118 days Microsoft Visual Studio Masked Edit Control ActiveX (Msmask32.ocx) Mask Parameter Overflow
829 2001-07-02 117 days IBM WebSphere Application Server (WAS) Java Servlet Error Page XSS
42946 2008-03-10 115 days RealPlayer ActiveX (rmoc3260.dll) Console Property Memory Corruption Arbitrary Code Execution
67543 2010-08-24 112 days Microsoft Windows Movie Maker Path Subversion Arbitrary OCX Injection Code Execution
31882 2006-10-27 112 days Microsoft MDAC ADODB.Connection ActiveX Control Execute Method Remote Code Execution
67722 2010-08-25 111 days Microsoft Windows Internet Connection Signup Wizard Path Subversion Arbitrary DLL Injection Code Execution
69942 2010-12-22 111 days Microsoft WMI Administrative Tools WEBSingleView.ocx ActiveX Remote Code Execution
1887 2001-07-02 107 days IBM Lotus Domino Server NSF Handling URI XSS
75375 2011-09-12 107 days ScadaTec Multiple Products Project Import ZIP File Handling Overflow
77157 2011-07-31 107 days obSuggest Component for Joomla! index.php controller Parameter Traversal Local File Inclusion
5248 2004-04-13 103 days Microsoft Windows LSASS Remote Overflow
74414 2011-08-06 101 days AChecker user/user_create_edit.php id Parameter SQL Injection
74415 2011-08-06 101 days AChecker themes/default/language/language_add_edit.tmpl.php id Parameter XSS
74416 2011-08-06 101 days AChecker themes/default/user/user_group_create_edit.tmpl.php id Parameter XSS
74417 2011-08-06 101 days AChecker documentation/frame_header.php p Parameter XSS
74418 2011-08-06 101 days AChecker updater/patch_edit.php myown_patch_id Parameter XSS
74419 2011-08-06 101 days AChecker user/user_create_edit.php id Parameter XSS
38975 2007-09-11 101 days X-Cart customer/product.php xcart_dir Parameter Remote File Inclusion
74413 2011-08-06 101 days AChecker updater/patch_edit.php myown_patch_id Parameter SQL Injection
68585 2010-10-12 99 days Microsoft Foundation Classes (MFC) Library Window Title Handling Remote Overflow
28370 2006-08-11 88 days Novell eDirectory iManager Log File Cleartext Password Disclosure
27110 2006-07-17 85 days Microsoft IE WebViewFolderIcon setSlice Overflow
66160 2010-07-02 74 days Microsoft IIS Basic Authentication NTFS Stream Name Permissions Bypass
2019 2002-01-08 74 days YaBB IMG Tag XSS
53242 2009-01-21 73 days HP OpenView Network Node Manager (OV NNM) OvCgi/Toolbar.exe Multiple Cookie Handling Overflow
10882 1998-08-23 70 days Sun AnswerBook2 Web Server dwhttpd HTTP GET Request Format String DoS
40269 2007-11-07 70 days CA eTrust SiteMinder Agent forms/smpwservices.fcc SMAUTHREASON Parameter XSS
43971 2007-09-07 68 days Apple Safari document.location.hash String Handling Remote Overflow
65484 2010-06-12 67 days Collabtive managechat.php uid Parameter SQL Injection
33270 2006-12-12 63 days Microsoft Word Unspecified Memory Corruption Arbitrary Code Execution
54600 2009-05-20 62 days IPplan admin/usermanager grp Parameter XSS
10039 2004-09-16 61 days DNS4Me Web Server GET Request Overflow DoS
67500 2010-08-24 59 days Microsoft Windows Live Mail Path Subversion Arbitrary DLL Injection Code Execution
73257 2011-05-01 58 days Asterisk SIP Multiple Message Response Username Enumeration
71773 2011-02-14 57 days Microsoft Windows Common Internet File System (CIFS) Malformed Browser Message Handling Overflow
19093 2005-08-17 55 days Microsoft Design Tools msdds.dll COM Object Arbitrary Code Execution
64347 2010-04-27 49 days Free Realty agentadmin.php Multiple Parameter SQL Injection Authentication Bypass
74455 2011-08-06 48 days AContent /documentation/frame_header.php p Parameter XSS
74456 2011-08-06 48 days AContent /documentation/frame_content.php p Parameter XSS

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2012 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use