Vulnerabilities > Activewebsoftwares

DATE CVE VULNERABILITY TITLE RISK
2010-06-21 CVE-2010-2359 SQL Injection vulnerability in Activewebsoftwares Ewebquiz 8.0
SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different vector than CVE-2007-1706.
network
low complexity
activewebsoftwares CWE-89
7.5
2009-12-30 CVE-2009-4464 Cross-Site Scripting vulnerability in Activewebsoftwares Active Business Directory 2.0
Cross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
4.3
2009-12-28 CVE-2009-4437 SQL Injection vulnerability in Activewebsoftwares Active Auction House 3.6
Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to wishlist.asp and the (2) linkid parameter to links.asp.
network
low complexity
activewebsoftwares CWE-89
7.5
2009-12-28 CVE-2009-4436 SQL Injection vulnerability in Activewebsoftwares Ewebquiz 8.0
Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2) importquestions.asp, and (3) quiztakers.asp, different vectors than CVE-2007-1706.
network
low complexity
activewebsoftwares CWE-89
7.5
2009-12-08 CVE-2009-4229 SQL Injection vulnerability in Activewebsoftwares Active Bids
Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter in the PATH_INFO to the default URI or (2) the catid parameter to default.asp.
network
low complexity
activewebsoftwares CWE-89
7.5
2009-08-03 CVE-2008-6889 SQL Injection vulnerability in Activewebsoftwares Aspreferral 5.3
SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter.
network
low complexity
activewebsoftwares CWE-89
7.5
2009-07-23 CVE-2008-6873 SQL Injection vulnerability in Activewebsoftwares Active web Mail 4.0
SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) addressbook.aspx, and (3) emails.aspx.
network
low complexity
activewebsoftwares CWE-89
7.5
2009-03-02 CVE-2008-6387 Information Exposure vulnerability in Activewebsoftwares Quick Tree View .Net 3.1
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to qtv.mdb.
network
low complexity
activewebsoftwares CWE-200
5.0
2009-03-02 CVE-2008-6380 SQL Injection vulnerability in Activewebsoftwares Active web Helpdesk 2.0
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
network
low complexity
activewebsoftwares CWE-89
7.5
2009-02-25 CVE-2008-6286 SQL Injection vulnerability in Activewebsoftwares Active Newsletter 4.3
Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the password parameter (aka password field), to (a) Subscriber.asp or (b) start.asp.
network
low complexity
activewebsoftwares CWE-89
7.5