Vulnerabilities > Ajsquare

DATE CVE VULNERABILITY TITLE RISK
2009-08-24 CVE-2008-7046 Improper Authentication vulnerability in Ajsquare Free Polling Script
AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/include/newpoll.php, a different vector than CVE-2008-7045.
network
low complexity
ajsquare CWE-287
6.4
2009-08-24 CVE-2008-7045 Improper Authentication vulnerability in Ajsquare Free Polling Script
AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct request to admin/resetvote.php.
network
low complexity
ajsquare CWE-287
6.4
2009-08-24 CVE-2008-7044 SQL Injection vulnerability in Ajsquare Free Polling Script
SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to execute arbitrary SQL commands via the ques parameter.
network
low complexity
ajsquare CWE-89
7.5
2009-08-24 CVE-2008-7041 Improper Authentication vulnerability in Ajsquare AJ Classifieds
AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.
network
low complexity
ajsquare CWE-287
7.5
2009-08-17 CVE-2009-2779 SQL Injection vulnerability in Ajsquare AJ Matrix DNA
SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in a productdetail action.
network
low complexity
ajsquare CWE-89
7.5
2009-04-14 CVE-2008-6721 SQL Injection vulnerability in Ajsquare AJ Article
SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName parameter (aka the username field).
network
low complexity
ajsquare CWE-89
7.5