Vulnerabilities > Activewebsoftwares > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2010-06-21 | CVE-2010-2359 | SQL Injection vulnerability in Activewebsoftwares Ewebquiz 8.0 SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different vector than CVE-2007-1706. | 7.5 |
2009-12-28 | CVE-2009-4437 | SQL Injection vulnerability in Activewebsoftwares Active Auction House 3.6 Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to wishlist.asp and the (2) linkid parameter to links.asp. | 7.5 |
2009-12-28 | CVE-2009-4436 | SQL Injection vulnerability in Activewebsoftwares Ewebquiz 8.0 Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2) importquestions.asp, and (3) quiztakers.asp, different vectors than CVE-2007-1706. | 7.5 |
2009-12-08 | CVE-2009-4229 | SQL Injection vulnerability in Activewebsoftwares Active Bids Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter in the PATH_INFO to the default URI or (2) the catid parameter to default.asp. | 7.5 |
2009-08-03 | CVE-2008-6889 | SQL Injection vulnerability in Activewebsoftwares Aspreferral 5.3 SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter. | 7.5 |
2009-07-23 | CVE-2008-6873 | SQL Injection vulnerability in Activewebsoftwares Active web Mail 4.0 SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) addressbook.aspx, and (3) emails.aspx. | 7.5 |
2009-03-02 | CVE-2008-6380 | SQL Injection vulnerability in Activewebsoftwares Active web Helpdesk 2.0 SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter. | 7.5 |
2009-02-25 | CVE-2008-6286 | SQL Injection vulnerability in Activewebsoftwares Active Newsletter 4.3 Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the password parameter (aka password field), to (a) Subscriber.asp or (b) start.asp. | 7.5 |
2009-02-05 | CVE-2009-0429 | SQL Injection vulnerability in Activewebsoftwares Active Bids Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to search.asp, (2) SortDir parameter to auctionsended.asp, and the (3) catid parameter to wishlist.php. | 7.5 |
2009-01-27 | CVE-2008-5975 | SQL Injection vulnerability in Activewebsoftwares Active Price Comparison 4.0 SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the linkid parameter. | 7.5 |