Записи activewebsoftwares
27 опубликованных записей вендора activewebsoftwares.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 24
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')24
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
27 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2008-5958Proof of concept | Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter activewebsoftwares · active test · CWE-89 | Высокая7,5 | — | 1,7 % | 23 янв. 2009 г. |
30Наблюдать | CVE-2008-5640Proof of concept | SQL injection vulnerability in bidhistory.asp in Active Bids 3.5 allows remote attackers to execute arbitrary SQL commands via the ItemID paactivewebsoftwares · active bids · CWE-89 | Высокая7,5 | — | 1,2 % | 17 дек. 2008 г. |
30Наблюдать | CVE-2008-5365Proof of concept | SQL injection vulnerability in VoteHistory.asp in ActiveWebSoftwares ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commanactivewebsoftwares · activevotes · CWE-89 | Высокая7,5 | — | 1,2 % | 8 дек. 2008 г. |
30Наблюдать | CVE-2009-4437Proof of concept | Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) catiactivewebsoftwares · active auction house · CWE-89 | Высокая7,5 | — | 1,0 % | 28 дек. 2009 г. |
30Наблюдать | CVE-2008-5632Proof of concept | SQL injection vulnerability in Account.asp in Active Time Billing 3.2 allows remote attackers to execute arbitrary SQL commands via the (1) activewebsoftwares · active time billing · CWE-89 | Высокая7,5 | — | 1,0 % | 17 дек. 2008 г. |
30Наблюдать | CVE-2008-5974Proof of concept | Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commandsactivewebsoftwares · active price comparison · CWE-89 | Высокая7,5 | — | 1,0 % | 26 янв. 2009 г. |
30Наблюдать | CVE-2008-5635Proof of concept | SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) usactivewebsoftwares · active membership · CWE-89 | Высокая7,5 | — | 1,0 % | 17 дек. 2008 г. |
30Наблюдать | CVE-2008-5634Proof of concept | SQL injection vulnerability in account.asp in Active Force Matrix 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) activewebsoftwares · active force matrix · CWE-89 | Высокая7,5 | — | 1,0 % | 17 дек. 2008 г. |
30Наблюдать | CVE-2008-5638Proof of concept | Multiple SQL injection vulnerabilities in Active Price Comparison 4 allow remote attackers to execute arbitrary SQL commands via the (1) Proactivewebsoftwares · active price comparison · CWE-89 | Высокая7,5 | — | 1,0 % | 17 дек. 2008 г. |
30Наблюдать | CVE-2008-5641Proof of concept | SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL commands via the (1)activewebsoftwares · active photo gallery · CWE-89 | Высокая7,5 | — | 1,0 % | 17 дек. 2008 г. |
30Наблюдать | CVE-2008-6889Proof of concept | SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL commands via the Accountactivewebsoftwares · aspreferral · CWE-89 | Высокая7,5 | — | 1,0 % | 3 авг. 2009 г. |
30Наблюдать | CVE-2008-5627Proof of concept | SQL injection vulnerability in account.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands via the (1) username activewebsoftwares · active trade · CWE-89 | Высокая7,5 | — | 1,0 % | 17 дек. 2008 г. |
30Наблюдать | CVE-2008-5973Proof of concept | SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password activewebsoftwares · active web mail · CWE-89 | Высокая7,5 | — | 1,0 % | 26 янв. 2009 г. |
30Наблюдать | CVE-2008-5633Proof of concept | SQL injection vulnerability in register.asp in ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) usernamactivewebsoftwares · activevotes · CWE-89 | Высокая7,5 | — | 1,0 % | 17 дек. 2008 г. |
30Наблюдать | CVE-2008-6286Proof of concept | Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commaactivewebsoftwares · active newsletter · CWE-89 | Высокая7,5 | — | 1,0 % | 25 февр. 2009 г. |
30Наблюдать | CVE-2008-6873Proof of concept | SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameactivewebsoftwares · active web mail · CWE-89 | Высокая7,5 | — | 1,0 % | 23 июл. 2009 г. |
30Наблюдать | CVE-2008-5631Proof of concept | SQL injection vulnerability in start.asp in Active eWebquiz 8.0 allows remote attackers to execute arbitrary SQL commands via the (1) useremactivewebsoftwares · active ewebquiz · CWE-89 | Высокая7,5 | — | 1,0 % | 17 дек. 2008 г. |
30Наблюдать | CVE-2010-2359Proof of concept | SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands vactivewebsoftwares · ewebquiz · CWE-89 | Высокая7,5 | — | 1,0 % | 21 июн. 2010 г. |
30Наблюдать | CVE-2008-5972Proof of concept | SQL injection vulnerability in default.asp in Active Business Directory 2 allows remote attackers to execute arbitrary SQL commands via the activewebsoftwares · active business directory · CWE-89 | Высокая7,5 | — | 1,0 % | 26 янв. 2009 г. |
30Наблюдать | CVE-2008-6380Proof of concept | SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the Catactivewebsoftwares · active web helpdesk · CWE-89 | Высокая7,5 | — | 1,0 % | 2 мар. 2009 г. |
30Наблюдать | CVE-2009-4436Proof of concept | Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the Qactivewebsoftwares · ewebquiz · CWE-89 | Высокая7,5 | — | 1,0 % | 28 дек. 2009 г. |
30Наблюдать | CVE-2008-5975Proof of concept | SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the liactivewebsoftwares · active price comparison · CWE-89 | Высокая7,5 | — | 1,0 % | 26 янв. 2009 г. |
30Наблюдать | CVE-2009-4229Proof of concept | Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL commands via (1) thactivewebsoftwares · active bids · CWE-89 | Высокая7,5 | — | 0,9 % | 8 дек. 2009 г. |
30Наблюдать | CVE-2009-0429Proof of concept | Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter activewebsoftwares · active bids · CWE-89 | Высокая7,5 | — | 0,9 % | 4 февр. 2009 г. |
21Наблюдать | CVE-2008-6387Proof of concept | Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to activewebsoftwares · quick tree view .net · CWE-200 | Средняя5,0 | — | 2,6 % | 2 мар. 2009 г. |
- CVE-2008-595831Наблюдать
Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %activewebsoftwares · active test23 янв. 2009 г.
- CVE-2008-564030Наблюдать
SQL injection vulnerability in bidhistory.asp in Active Bids 3.5 allows remote attackers to execute arbitrary SQL commands via the ItemID pa
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active bids17 дек. 2008 г.
- CVE-2008-536530Наблюдать
SQL injection vulnerability in VoteHistory.asp in ActiveWebSoftwares ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL comman
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · activevotes8 дек. 2008 г.
- CVE-2009-443730Наблюдать
Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) cati
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active auction house28 дек. 2009 г.
- CVE-2008-563230Наблюдать
SQL injection vulnerability in Account.asp in Active Time Billing 3.2 allows remote attackers to execute arbitrary SQL commands via the (1)
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active time billing17 дек. 2008 г.
- CVE-2008-597430Наблюдать
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active price comparison26 янв. 2009 г.
- CVE-2008-563530Наблюдать
SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) us
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active membership17 дек. 2008 г.
- CVE-2008-563430Наблюдать
SQL injection vulnerability in account.asp in Active Force Matrix 2.0 allows remote attackers to execute arbitrary SQL commands via the (1)
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active force matrix17 дек. 2008 г.
- CVE-2008-563830Наблюдать
Multiple SQL injection vulnerabilities in Active Price Comparison 4 allow remote attackers to execute arbitrary SQL commands via the (1) Pro
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active price comparison17 дек. 2008 г.
- CVE-2008-564130Наблюдать
SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL commands via the (1)
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active photo gallery17 дек. 2008 г.
- CVE-2008-688930Наблюдать
SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL commands via the Account
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · aspreferral3 авг. 2009 г.
- CVE-2008-562730Наблюдать
SQL injection vulnerability in account.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands via the (1) username
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active trade17 дек. 2008 г.
- CVE-2008-597330Наблюдать
SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active web mail26 янв. 2009 г.
- CVE-2008-563330Наблюдать
SQL injection vulnerability in register.asp in ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) usernam
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · activevotes17 дек. 2008 г.
- CVE-2008-628630Наблюдать
Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL comma
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active newsletter25 февр. 2009 г.
- CVE-2008-687330Наблюдать
SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parame
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active web mail23 июл. 2009 г.
- CVE-2008-563130Наблюдать
SQL injection vulnerability in start.asp in Active eWebquiz 8.0 allows remote attackers to execute arbitrary SQL commands via the (1) userem
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active ewebquiz17 дек. 2008 г.
- CVE-2010-235930Наблюдать
SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands v
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · ewebquiz21 июн. 2010 г.
- CVE-2008-597230Наблюдать
SQL injection vulnerability in default.asp in Active Business Directory 2 allows remote attackers to execute arbitrary SQL commands via the
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active business directory26 янв. 2009 г.
- CVE-2008-638030Наблюдать
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the Cat
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active web helpdesk2 мар. 2009 г.
- CVE-2009-443630Наблюдать
Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the Q
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · ewebquiz28 дек. 2009 г.
- CVE-2008-597530Наблюдать
SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the li
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active price comparison26 янв. 2009 г.
- CVE-2009-422930Наблюдать
Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL commands via (1) th
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active bids8 дек. 2009 г.
- CVE-2009-042930Наблюдать
Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %activewebsoftwares · active bids4 февр. 2009 г.
- CVE-2008-638721Наблюдать
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to
СредняяCVSS 5,0Proof of conceptEPSS 3 %activewebsoftwares · quick tree view .net2 мар. 2009 г.