Vulnerabilities > Activewebsoftwares > Active Price Comparison

DATE CVE VULNERABILITY TITLE RISK
2009-01-27 CVE-2008-5975 SQL Injection vulnerability in Activewebsoftwares Active Price Comparison 4.0
SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the linkid parameter.
network
low complexity
activewebsoftwares CWE-89
7.5
2009-01-27 CVE-2008-5974 SQL Injection vulnerability in Activewebsoftwares Active Price Comparison 4.0
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) username fields.
network
low complexity
activewebsoftwares CWE-89
7.5
2008-12-17 CVE-2008-5638 SQL Injection vulnerability in Activewebsoftwares Active Price Comparison 4.0
Multiple SQL injection vulnerabilities in Active Price Comparison 4 allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter to reviews.aspx or the (2) linkid parameter to links.asp.
network
low complexity
activewebsoftwares CWE-89
7.5