enthrallweb records
15 published records for vendor enthrallweb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 11
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-3027Proof of concept | Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via enthrallweb · ephotos | High7.5 | — | 2.7% | Jun 15, 2006 |
30Monitor | CVE-2006-6074No exploit | Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the Prenthrallweb · eshopping cart | High7.5 | — | 1.4% | Nov 24, 2006 |
30Monitor | CVE-2006-6208Proof of concept | Multiple SQL injection vulnerabilities in Enthrallweb eClassifieds allow remote attackers to execute arbitrary SQL commands via the (1) AD_Ienthrallweb · eclassifieds | High7.5 | — | 1.3% | Nov 30, 2006 |
30Monitor | CVE-2006-6204Proof of concept | Multiple SQL injection vulnerabilities in Enthrallweb eHomes allow remote attackers to execute arbitrary SQL commands via the (1) cid parameenthrallweb · ehomes | High7.5 | — | 1.3% | Nov 30, 2006 |
30Monitor | CVE-2006-6073No exploit | Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Prenthrallweb · eshopping cart · CWE-89 | High7.5 | — | 1.1% | Nov 24, 2006 |
30Monitor | CVE-2006-6805Proof of concept | SQL injection vulnerability in newsdetail.asp in Enthrallweb eJobs allows remote attackers to execute arbitrary SQL commands via the ID paraenthrallweb · ejobs | High7.5 | — | 1.1% | Dec 28, 2006 |
30Monitor | CVE-2006-6806Proof of concept | SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL commands via the IDenthrallweb · emates | High7.5 | — | 1.1% | Dec 28, 2006 |
30Monitor | CVE-2006-6802Proof of concept | SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL commands via the Biz_ID enthrallweb · epages | High7.5 | — | 1.1% | Dec 28, 2006 |
30Monitor | CVE-2006-6804Proof of concept | SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01enthrallweb · dragon business directory pro | High7.5 | — | 1.1% | Dec 28, 2006 |
30Monitor | CVE-2006-6803Proof of concept | SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL commands via the Type_id enthrallweb · ecars | High7.5 | — | 1.1% | Dec 28, 2006 |
30Monitor | CVE-2009-0252Proof of concept | Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands enthrallweb · ereservations · CWE-89 | High7.5 | — | 1.0% | Jan 22, 2009 |
28Monitor | CVE-2006-6205Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in result.asp in Enthrallweb eHomes allow remote attackers to inject arbitrary web scripenthrallweb · ehomes | Medium6.8 | — | 2.2% | Nov 30, 2006 |
15Monitor | CVE-2006-6820Proof of concept | myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which allows remote autheenthrallweb · ecoupons | Low3.5 | — | 1.8% | Dec 29, 2006 |
15Monitor | CVE-2006-6821Proof of concept | myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authentienthrallweb · enews | Low3.5 | — | 1.8% | Dec 29, 2006 |
15Monitor | CVE-2006-6822Proof of concept | myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote aenthrallweb · eclassifieds | Low3.5 | — | 1.8% | Dec 29, 2006 |
- CVE-2006-302731Monitor
Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 3%enthrallweb · ephotosJun 15, 2006
- CVE-2006-607430Monitor
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the Pr
HighCVSS 7.5No exploitEPSS 1%enthrallweb · eshopping cartNov 24, 2006
- CVE-2006-620830Monitor
Multiple SQL injection vulnerabilities in Enthrallweb eClassifieds allow remote attackers to execute arbitrary SQL commands via the (1) AD_I
HighCVSS 7.5Proof of conceptEPSS 1%enthrallweb · eclassifiedsNov 30, 2006
- CVE-2006-620430Monitor
Multiple SQL injection vulnerabilities in Enthrallweb eHomes allow remote attackers to execute arbitrary SQL commands via the (1) cid parame
HighCVSS 7.5Proof of conceptEPSS 1%enthrallweb · ehomesNov 30, 2006
- CVE-2006-607330Monitor
Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Pr
HighCVSS 7.5No exploitEPSS 1%enthrallweb · eshopping cartNov 24, 2006
- CVE-2006-680530Monitor
SQL injection vulnerability in newsdetail.asp in Enthrallweb eJobs allows remote attackers to execute arbitrary SQL commands via the ID para
HighCVSS 7.5Proof of conceptEPSS 1%enthrallweb · ejobsDec 28, 2006
- CVE-2006-680630Monitor
SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL commands via the ID
HighCVSS 7.5Proof of conceptEPSS 1%enthrallweb · ematesDec 28, 2006
- CVE-2006-680230Monitor
SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL commands via the Biz_ID
HighCVSS 7.5Proof of conceptEPSS 1%enthrallweb · epagesDec 28, 2006
- CVE-2006-680430Monitor
SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01
HighCVSS 7.5Proof of conceptEPSS 1%enthrallweb · dragon business directory proDec 28, 2006
- CVE-2006-680330Monitor
SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL commands via the Type_id
HighCVSS 7.5Proof of conceptEPSS 1%enthrallweb · ecarsDec 28, 2006
- CVE-2009-025230Monitor
Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands
HighCVSS 7.5Proof of conceptEPSS 1%enthrallweb · ereservationsJan 22, 2009
- CVE-2006-620528Monitor
Multiple cross-site scripting (XSS) vulnerabilities in result.asp in Enthrallweb eHomes allow remote attackers to inject arbitrary web scrip
MediumCVSS 6.8Proof of conceptEPSS 2%enthrallweb · ehomesNov 30, 2006
- CVE-2006-682015Monitor
myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which allows remote authe
LowCVSS 3.5Proof of conceptEPSS 2%enthrallweb · ecouponsDec 29, 2006
- CVE-2006-682115Monitor
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenti
LowCVSS 3.5Proof of conceptEPSS 2%enthrallweb · enewsDec 29, 2006
- CVE-2006-682215Monitor
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote a
LowCVSS 3.5Proof of conceptEPSS 2%enthrallweb · eclassifiedsDec 29, 2006