Skip to content
Noroxi

ajsquare records

16 published records for vendor ajsquare.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
7
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

16 records
  • CVE-2008-7041
    31Monitor

    AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.

    HighCVSS 7.5Proof of conceptEPSS 3%

    ajsquare · aj classifiedsAug 24, 2009

  • CVE-2008-7051
    31Monitor

    AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) use

    HighCVSS 7.5Proof of conceptEPSS 3%

    ajsquare · aj articleAug 24, 2009

  • CVE-2008-7044
    30Monitor

    SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers

    HighCVSS 7.5Proof of conceptEPSS 1%

    ajsquare · free polling scriptAug 24, 2009

  • CVE-2009-2779
    30Monitor

    SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in

    HighCVSS 7.5Proof of conceptEPSS 1%

    ajsquare · aj matrix dnaAug 17, 2009

  • CVE-2009-3203
    30Monitor

    SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id par

    HighCVSS 7.5Proof of conceptEPSS 1%

    ajsquare · aj auction pro-oopdSep 16, 2009

  • CVE-2010-1876
    30Monitor

    SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid

    HighCVSS 7.5Proof of conceptEPSS 1%

    ajsquare · aj shopping cartMay 12, 2010

  • CVE-2010-2915
    30Monitor

    SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id p

    HighCVSS 7.5Proof of conceptEPSS 1%

    ajsquare · aj hyipJul 30, 2010

  • CVE-2008-6721
    30Monitor

    SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName p

    HighCVSS 7.5Proof of conceptEPSS 1%

    ajsquare · aj articleApr 14, 2009

  • CVE-2010-2916
    30Monitor

    SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id p

    HighCVSS 7.5Proof of conceptEPSS 1%

    ajsquare · aj hyipJul 30, 2010

  • CVE-2008-7045
    26Monitor

    AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct r

    MediumCVSS 6.4Proof of conceptEPSS 3%

    ajsquare · free polling scriptAug 24, 2009

  • CVE-2008-7046
    26Monitor

    AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/i

    MediumCVSS 6.4Proof of conceptEPSS 2%

    ajsquare · free polling scriptAug 24, 2009

  • CVE-2015-2184
    23Monitor

    ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function.

    MediumCVSS 5.0Proof of conceptEPSS 8%

    ajsquare · zeuscartMar 10, 2015

  • CVE-2015-2182
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script or HTML via the (1)

    MediumCVSS 4.3Proof of conceptEPSS 4%

    ajsquare · zeuscartMar 11, 2015

  • CVE-2010-5322
    18Monitor

    Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the

    MediumCVSS 4.3Proof of conceptEPSS 3%

    ajsquare · zeuscartMar 11, 2015

  • CVE-2010-2917
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web

    MediumCVSS 4.3Proof of conceptEPSS 2%

    ajsquare · aj articleJul 30, 2010

  • CVE-2009-4989
    17Monitor

    Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or H

    MediumCVSS 4.3Proof of conceptEPSS 1%

    ajsquare · aj auction pro-oopdAug 25, 2010