CVE Tools

Enthrallweb

15 CVEs tracked since 2006. Since Jun 2006, none of them reached CISA KEV.

Enthrallweb CVEs per month

Jun 2006 to Jan 2009. Point at a month, or focus the strip and use the arrow keys.
Enthrallweb CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2006-0610
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-1120
2006-12110
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-03null or fewer
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-0110

Products

The products that kept showing up in Enthrallweb's monthly top three, with their CVEs summed over those months.

  1. Eclassifieds21 month
  2. Ehomes21 month
  3. Eshopping Cart21 month
  4. Epages11 month
  5. Ephotos11 month
  6. Ereservations11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Enthrallweb.

  1. CVE-2009-0252Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (...7.5
  2. CVE-2006-6821myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another a...3.5
  3. CVE-2006-6820myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of anothe...3.5
  4. CVE-2006-6822myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of an...3.5
  5. CVE-2006-6805SQL injection vulnerability in newsdetail.asp in Enthrallweb eJobs allows remote attackers to execute arbitrary SQL commands via the ID parameter.7.5
  6. CVE-2006-6806SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.7.5
  7. CVE-2006-6802SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL commands via the Biz_ID parameter.7.5
  8. CVE-2006-6804SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01.12 and earlier allows remote attackers to execute arbitr...7.5
  9. CVE-2006-6803SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL commands via the Type_id parameter.7.5
  10. CVE-2006-6208Multiple SQL injection vulnerabilities in Enthrallweb eClassifieds allow remote attackers to execute arbitrary SQL commands via the (1) AD_ID, (2) cat_id, (3) sub_id, and (4) ad_id parameters to (a...7.5
  11. CVE-2006-6205Multiple cross-site scripting (XSS) vulnerabilities in result.asp in Enthrallweb eHomes allow remote attackers to inject arbitrary web script or HTML via the (1) city or (2) State parameter.6.8
  12. CVE-2006-6204Multiple SQL injection vulnerabilities in Enthrallweb eHomes allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to (a) dircat.asp; the (2) sid parameter to (b) dirSu...7.5
  13. CVE-2006-6073Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter in productdetail.asp or the (2) categor...7.5
  14. CVE-2006-6074Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the ProductID parameter in (a) reviews.asp, or the (2) cat_id o...7.5
  15. CVE-2006-3027Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) CAT_ID parameter in (a) subphotos.asp and (b) sub...7.5

The record

Peak rank
#4 in Dec 2006
Busiest month shown
Dec 2006, 11 CVEs
Months with a KEV entry
0 since Jun 2006
Monthly snapshots
4 since 2006
Enthrallweb's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store