activewebsoftwares records
27 published records for vendor activewebsoftwares.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 24
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')24
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2008-5958Proof of concept | Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter activewebsoftwares · active test · CWE-89 | High7.5 | — | 1.7% | Jan 23, 2009 |
30Monitor | CVE-2008-5640Proof of concept | SQL injection vulnerability in bidhistory.asp in Active Bids 3.5 allows remote attackers to execute arbitrary SQL commands via the ItemID paactivewebsoftwares · active bids · CWE-89 | High7.5 | — | 1.2% | Dec 17, 2008 |
30Monitor | CVE-2008-5365Proof of concept | SQL injection vulnerability in VoteHistory.asp in ActiveWebSoftwares ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commanactivewebsoftwares · activevotes · CWE-89 | High7.5 | — | 1.2% | Dec 8, 2008 |
30Monitor | CVE-2009-4437Proof of concept | Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) catiactivewebsoftwares · active auction house · CWE-89 | High7.5 | — | 1.0% | Dec 28, 2009 |
30Monitor | CVE-2008-5632Proof of concept | SQL injection vulnerability in Account.asp in Active Time Billing 3.2 allows remote attackers to execute arbitrary SQL commands via the (1) activewebsoftwares · active time billing · CWE-89 | High7.5 | — | 1.0% | Dec 17, 2008 |
30Monitor | CVE-2008-5974Proof of concept | Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commandsactivewebsoftwares · active price comparison · CWE-89 | High7.5 | — | 1.0% | Jan 26, 2009 |
30Monitor | CVE-2008-5635Proof of concept | SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) usactivewebsoftwares · active membership · CWE-89 | High7.5 | — | 1.0% | Dec 17, 2008 |
30Monitor | CVE-2008-5634Proof of concept | SQL injection vulnerability in account.asp in Active Force Matrix 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) activewebsoftwares · active force matrix · CWE-89 | High7.5 | — | 1.0% | Dec 17, 2008 |
30Monitor | CVE-2008-5638Proof of concept | Multiple SQL injection vulnerabilities in Active Price Comparison 4 allow remote attackers to execute arbitrary SQL commands via the (1) Proactivewebsoftwares · active price comparison · CWE-89 | High7.5 | — | 1.0% | Dec 17, 2008 |
30Monitor | CVE-2008-5641Proof of concept | SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL commands via the (1)activewebsoftwares · active photo gallery · CWE-89 | High7.5 | — | 1.0% | Dec 17, 2008 |
30Monitor | CVE-2008-6889Proof of concept | SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL commands via the Accountactivewebsoftwares · aspreferral · CWE-89 | High7.5 | — | 1.0% | Aug 3, 2009 |
30Monitor | CVE-2008-5627Proof of concept | SQL injection vulnerability in account.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands via the (1) username activewebsoftwares · active trade · CWE-89 | High7.5 | — | 1.0% | Dec 17, 2008 |
30Monitor | CVE-2008-5973Proof of concept | SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password activewebsoftwares · active web mail · CWE-89 | High7.5 | — | 1.0% | Jan 26, 2009 |
30Monitor | CVE-2008-5633Proof of concept | SQL injection vulnerability in register.asp in ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) usernamactivewebsoftwares · activevotes · CWE-89 | High7.5 | — | 1.0% | Dec 17, 2008 |
30Monitor | CVE-2008-6286Proof of concept | Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commaactivewebsoftwares · active newsletter · CWE-89 | High7.5 | — | 1.0% | Feb 25, 2009 |
30Monitor | CVE-2008-6873Proof of concept | SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameactivewebsoftwares · active web mail · CWE-89 | High7.5 | — | 1.0% | Jul 23, 2009 |
30Monitor | CVE-2008-5631Proof of concept | SQL injection vulnerability in start.asp in Active eWebquiz 8.0 allows remote attackers to execute arbitrary SQL commands via the (1) useremactivewebsoftwares · active ewebquiz · CWE-89 | High7.5 | — | 1.0% | Dec 17, 2008 |
30Monitor | CVE-2010-2359Proof of concept | SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands vactivewebsoftwares · ewebquiz · CWE-89 | High7.5 | — | 1.0% | Jun 21, 2010 |
30Monitor | CVE-2008-5972Proof of concept | SQL injection vulnerability in default.asp in Active Business Directory 2 allows remote attackers to execute arbitrary SQL commands via the activewebsoftwares · active business directory · CWE-89 | High7.5 | — | 1.0% | Jan 26, 2009 |
30Monitor | CVE-2008-6380Proof of concept | SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the Catactivewebsoftwares · active web helpdesk · CWE-89 | High7.5 | — | 1.0% | Mar 2, 2009 |
30Monitor | CVE-2009-4436Proof of concept | Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the Qactivewebsoftwares · ewebquiz · CWE-89 | High7.5 | — | 1.0% | Dec 28, 2009 |
30Monitor | CVE-2008-5975Proof of concept | SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the liactivewebsoftwares · active price comparison · CWE-89 | High7.5 | — | 1.0% | Jan 26, 2009 |
30Monitor | CVE-2009-4229Proof of concept | Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL commands via (1) thactivewebsoftwares · active bids · CWE-89 | High7.5 | — | 0.9% | Dec 8, 2009 |
30Monitor | CVE-2009-0429Proof of concept | Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter activewebsoftwares · active bids · CWE-89 | High7.5 | — | 0.9% | Feb 4, 2009 |
21Monitor | CVE-2008-6387Proof of concept | Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to activewebsoftwares · quick tree view .net · CWE-200 | Medium5.0 | — | 2.6% | Mar 2, 2009 |
- CVE-2008-595831Monitor
Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter
HighCVSS 7.5Proof of conceptEPSS 2%activewebsoftwares · active testJan 23, 2009
- CVE-2008-564030Monitor
SQL injection vulnerability in bidhistory.asp in Active Bids 3.5 allows remote attackers to execute arbitrary SQL commands via the ItemID pa
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active bidsDec 17, 2008
- CVE-2008-536530Monitor
SQL injection vulnerability in VoteHistory.asp in ActiveWebSoftwares ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL comman
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · activevotesDec 8, 2008
- CVE-2009-443730Monitor
Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) cati
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active auction houseDec 28, 2009
- CVE-2008-563230Monitor
SQL injection vulnerability in Account.asp in Active Time Billing 3.2 allows remote attackers to execute arbitrary SQL commands via the (1)
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active time billingDec 17, 2008
- CVE-2008-597430Monitor
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active price comparisonJan 26, 2009
- CVE-2008-563530Monitor
SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) us
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active membershipDec 17, 2008
- CVE-2008-563430Monitor
SQL injection vulnerability in account.asp in Active Force Matrix 2.0 allows remote attackers to execute arbitrary SQL commands via the (1)
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active force matrixDec 17, 2008
- CVE-2008-563830Monitor
Multiple SQL injection vulnerabilities in Active Price Comparison 4 allow remote attackers to execute arbitrary SQL commands via the (1) Pro
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active price comparisonDec 17, 2008
- CVE-2008-564130Monitor
SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL commands via the (1)
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active photo galleryDec 17, 2008
- CVE-2008-688930Monitor
SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL commands via the Account
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · aspreferralAug 3, 2009
- CVE-2008-562730Monitor
SQL injection vulnerability in account.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands via the (1) username
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active tradeDec 17, 2008
- CVE-2008-597330Monitor
SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active web mailJan 26, 2009
- CVE-2008-563330Monitor
SQL injection vulnerability in register.asp in ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) usernam
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · activevotesDec 17, 2008
- CVE-2008-628630Monitor
Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL comma
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active newsletterFeb 25, 2009
- CVE-2008-687330Monitor
SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parame
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active web mailJul 23, 2009
- CVE-2008-563130Monitor
SQL injection vulnerability in start.asp in Active eWebquiz 8.0 allows remote attackers to execute arbitrary SQL commands via the (1) userem
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active ewebquizDec 17, 2008
- CVE-2010-235930Monitor
SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands v
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · ewebquizJun 21, 2010
- CVE-2008-597230Monitor
SQL injection vulnerability in default.asp in Active Business Directory 2 allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active business directoryJan 26, 2009
- CVE-2008-638030Monitor
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the Cat
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active web helpdeskMar 2, 2009
- CVE-2009-443630Monitor
Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the Q
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · ewebquizDec 28, 2009
- CVE-2008-597530Monitor
SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the li
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active price comparisonJan 26, 2009
- CVE-2009-422930Monitor
Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL commands via (1) th
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active bidsDec 8, 2009
- CVE-2009-042930Monitor
Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter
HighCVSS 7.5Proof of conceptEPSS 1%activewebsoftwares · active bidsFeb 4, 2009
- CVE-2008-638721Monitor
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to
MediumCVSS 5.0Proof of conceptEPSS 3%activewebsoftwares · quick tree view .netMar 2, 2009