Skip to content
Noroxi

enthrallweb records

15 published records for vendor enthrallweb.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
11
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    15 records
    • CVE-2006-3027
      31Monitor

      Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via

      HighCVSS 7.5Proof of conceptEPSS 3%

      enthrallweb · ephotosJun 15, 2006

    • CVE-2006-6074
      30Monitor

      Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the Pr

      HighCVSS 7.5No exploitEPSS 1%

      enthrallweb · eshopping cartNov 24, 2006

    • CVE-2006-6208
      30Monitor

      Multiple SQL injection vulnerabilities in Enthrallweb eClassifieds allow remote attackers to execute arbitrary SQL commands via the (1) AD_I

      HighCVSS 7.5Proof of conceptEPSS 1%

      enthrallweb · eclassifiedsNov 30, 2006

    • CVE-2006-6204
      30Monitor

      Multiple SQL injection vulnerabilities in Enthrallweb eHomes allow remote attackers to execute arbitrary SQL commands via the (1) cid parame

      HighCVSS 7.5Proof of conceptEPSS 1%

      enthrallweb · ehomesNov 30, 2006

    • CVE-2006-6073
      30Monitor

      Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Pr

      HighCVSS 7.5No exploitEPSS 1%

      enthrallweb · eshopping cartNov 24, 2006

    • CVE-2006-6805
      30Monitor

      SQL injection vulnerability in newsdetail.asp in Enthrallweb eJobs allows remote attackers to execute arbitrary SQL commands via the ID para

      HighCVSS 7.5Proof of conceptEPSS 1%

      enthrallweb · ejobsDec 28, 2006

    • CVE-2006-6806
      30Monitor

      SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL commands via the ID

      HighCVSS 7.5Proof of conceptEPSS 1%

      enthrallweb · ematesDec 28, 2006

    • CVE-2006-6802
      30Monitor

      SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL commands via the Biz_ID

      HighCVSS 7.5Proof of conceptEPSS 1%

      enthrallweb · epagesDec 28, 2006

    • CVE-2006-6804
      30Monitor

      SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01

      HighCVSS 7.5Proof of conceptEPSS 1%

      enthrallweb · dragon business directory proDec 28, 2006

    • CVE-2006-6803
      30Monitor

      SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL commands via the Type_id

      HighCVSS 7.5Proof of conceptEPSS 1%

      enthrallweb · ecarsDec 28, 2006

    • CVE-2009-0252
      30Monitor

      Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands

      HighCVSS 7.5Proof of conceptEPSS 1%

      enthrallweb · ereservationsJan 22, 2009

    • CVE-2006-6205
      28Monitor

      Multiple cross-site scripting (XSS) vulnerabilities in result.asp in Enthrallweb eHomes allow remote attackers to inject arbitrary web scrip

      MediumCVSS 6.8Proof of conceptEPSS 2%

      enthrallweb · ehomesNov 30, 2006

    • CVE-2006-6820
      15Monitor

      myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which allows remote authe

      LowCVSS 3.5Proof of conceptEPSS 2%

      enthrallweb · ecouponsDec 29, 2006

    • CVE-2006-6821
      15Monitor

      myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenti

      LowCVSS 3.5Proof of conceptEPSS 2%

      enthrallweb · enewsDec 29, 2006

    • CVE-2006-6822
      15Monitor

      myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote a

      LowCVSS 3.5Proof of conceptEPSS 2%

      enthrallweb · eclassifiedsDec 29, 2006