Vulnerabilities > Myiosoft

DATE CVE VULNERABILITY TITLE RISK
2009-06-30 CVE-2009-2262 Code Injection vulnerability in Myiosoft Ajaxportal 3.0
PHP remote file inclusion vulnerability in install/di.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the pathtoserverdata parameter.
network
low complexity
myiosoft CWE-94
7.5
2009-05-01 CVE-2009-1509 SQL Injection vulnerability in Myiosoft Ajaxportal 3.0
SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
network
low complexity
myiosoft CWE-89
7.5
2008-12-17 CVE-2008-5655 SQL Injection vulnerability in Myiosoft Easybookmarker 4.0
Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link parameters to unspecified vectors, possibly to (a) plugins/bookmarker/bookmarker_backend.php or (b) ajaxp.php, different vectors than CVE-2008-5654.
network
low complexity
myiosoft CWE-89
7.5
2008-12-17 CVE-2008-5654 SQL Injection vulnerability in Myiosoft Easycalendar 4.0
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter, a different vector than CVE-2008-1344.
network
low complexity
myiosoft CWE-89
7.5
2008-12-17 CVE-2008-5652 SQL Injection vulnerability in Myiosoft Easybookmarker 4.0
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter.
network
low complexity
myiosoft CWE-89
7.5
2008-12-17 CVE-2008-5651 SQL Injection vulnerability in Myiosoft Easybookmarker 4.0
SQL injection vulnerability in plugins/bookmarker/bookmarker_backend.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the Parent parameter.
network
low complexity
myiosoft CWE-89
7.5
2008-09-15 CVE-2008-4084 SQL Injection vulnerability in Myiosoft Easyclassifields 3.0
SQL injection vulnerability in staticpages/easyclassifields/index.php in MyioSoft EasyClassifields 3.0 allows remote attackers to execute arbitrary SQL commands via the go parameter in a browse action.
network
myiosoft CWE-89
6.8
2008-07-30 CVE-2008-3380 Cross-Site Scripting vulnerability in Myiosoft Easybookmarker 4.0
Cross-site scripting (XSS) vulnerability in ajaxp_backend.php in MyioSoft EasyBookMarker 4.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the rs parameter.
network
myiosoft CWE-79
4.3
2008-07-28 CVE-2008-3348 Cross-Site Scripting vulnerability in Myiosoft Easydynamicpages 3.0
Cross-site scripting (XSS) vulnerability in staticpages/easycalendar/index.php in MyioSoft EasyDynamicPages 3.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the year parameter.
network
myiosoft CWE-79
4.3
2008-07-28 CVE-2008-3347 SQL Injection vulnerability in Myiosoft Easydynamicpages 3.0
SQL injection vulnerability in staticpages/easycalendar/index.php in MyioSoft EasyDynamicPages 3.0 trial edition (tr) allows remote attackers to execute arbitrary SQL commands via the read parameter.
network
low complexity
myiosoft CWE-89
7.5