Activewebsoftwares
26 CVEs tracked since 2008. Since Dec 2008, none of them reached CISA KEV.
Activewebsoftwares CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2008-12 | 10 | 0 |
| 2009-01 | 5 | 0 |
| 2009-02 | 3 | 0 |
| 2009-03 | 2 | 0 |
| 2009-04 | null or fewer | |
| 2009-05 | null or fewer | |
| 2009-06 | null or fewer | |
| 2009-07 | 1 | 0 |
| 2009-08 | null or fewer | |
| 2009-09 | null or fewer | |
| 2009-10 | null or fewer | |
| 2009-11 | null or fewer | |
| 2009-12 | 4 | 0 |
| 2010-01 | null or fewer | |
| 2010-02 | null or fewer | |
| 2010-03 | null or fewer | |
| 2010-04 | null or fewer | |
| 2010-05 | null or fewer | |
| 2010-06 | 1 | 0 |
Products
The products that kept showing up in Activewebsoftwares's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Activewebsoftwares.
- CVE-2010-2359SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different vector than CVE-20...7.5
- CVE-2009-4464Cross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.4.3
- CVE-2009-4437Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to wishlist.asp and the (2) linkid parameter ...7.5
- CVE-2009-4436Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2) importquestions...7.5
- CVE-2009-4229Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter in the PATH_INFO to the default URI or ...7.5
- CVE-2008-6889SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter.7.5
- CVE-2008-6873SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) addressbook.aspx, and (3...7.5
- CVE-2008-6380SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.7.5
- CVE-2008-6387Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to qtv.mdb.5.0
- CVE-2008-6286Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail f...7.5
- CVE-2009-0429Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to search.asp, (2) SortDir parameter to auctionsended.asp...7.5
- CVE-2009-0430Multiple cross-site scripting (XSS) vulnerabilities in Active Bids allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to search.asp and the (2) URL parameter...4.3
- CVE-2008-5975SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the linkid parameter. NOTE: the provenance of this information...7.5
- CVE-2008-5974Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) username fields.7.5
- CVE-2008-5973SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.7.5
The record
- Peak rank
- #8 in Dec 2008
- Busiest month shown
- Dec 2008, 10 CVEs
- Months with a KEV entry
- 0 since Dec 2008
- Monthly snapshots
- 7 since 2008