Vulnerabilities > Digiappz

DATE CVE VULNERABILITY TITLE RISK
2009-03-18 CVE-2008-6487 SQL Injection vulnerability in Digiappz Digiaffiliate
Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin and (2) password fields.
network
low complexity
digiappz CWE-89
7.5
2008-07-25 CVE-2008-3309 SQL Injection vulnerability in Digiappz Digileave
SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter.
network
low complexity
digiappz CWE-89
7.5
2008-03-31 CVE-2008-1560 Cross-Site Scripting vulnerability in Digiappz Digidomain 2.2
Multiple cross-site scripting (XSS) vulnerabilities in Digiappz DigiDomain 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) domain parameter to lookup_result.asp, and the (2) word1 and (3) word2 parameters to suggest_result.asp.
network
digiappz CWE-79
4.3
2007-05-29 CVE-2007-2880 Cross-Site Scripting vulnerability in Digiappz Digirez 3.4
Multiple cross-site scripting (XSS) vulnerabilities in Digirez 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Room_name parameter to room/info_book.asp or the (2) curYear parameter to room/week.asp.
network
digiappz
4.3
2007-01-18 CVE-2007-0306 SQL Injection vulnerability in DigiAppz DigiAffiliate Visu_User.ASP
SQL injection vulnerability in visu_user.asp in Digiappz DigiAffiliate 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
digiappz
7.5
2007-01-09 CVE-2007-0128 SQL-Injection vulnerability in Digirez
SQL injection vulnerability in info_book.asp in Digirez 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter.
network
low complexity
digiappz
7.5
2006-09-01 CVE-2006-4524 SQL Injection vulnerability in Digiappz Freekot 1.01
Multiple SQL injection vulnerabilities in login_verif.asp in Digiappz Freekot 1.01 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) password parameters.
network
low complexity
digiappz
7.5