Vulnerabilities > Activewebsoftwares > Active Price Comparison > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-01-27 | CVE-2008-5975 | SQL Injection vulnerability in Activewebsoftwares Active Price Comparison 4.0 SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the linkid parameter. | 7.5 |
2009-01-27 | CVE-2008-5974 | SQL Injection vulnerability in Activewebsoftwares Active Price Comparison 4.0 Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) username fields. | 7.5 |
2008-12-17 | CVE-2008-5638 | SQL Injection vulnerability in Activewebsoftwares Active Price Comparison 4.0 Multiple SQL injection vulnerabilities in Active Price Comparison 4 allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter to reviews.aspx or the (2) linkid parameter to links.asp. | 7.5 |