Vulnerabilities (CVE)

Filtered by vendor Activewebsoftwares Subscribe
Total 27 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6873 1 Activewebsoftwares 1 Active Web Mail 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) addressbook.aspx, and (3) emails.aspx.
CVE-2008-5634 1 Activewebsoftwares 1 Active Force Matrix 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in account.asp in Active Force Matrix 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.
CVE-2008-5638 1 Activewebsoftwares 1 Active Price Comparison 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Active Price Comparison 4 allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter to reviews.aspx or the (2) linkid parameter to links.asp.
CVE-2008-5973 1 Activewebsoftwares 1 Active Web Mail 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.
CVE-2008-6380 1 Activewebsoftwares 1 Active Web Helpdesk 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
CVE-2008-5974 1 Activewebsoftwares 1 Active Price Comparison 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) username fields.
CVE-2008-5627 1 Activewebsoftwares 1 Active Trade 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in account.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter (aka Email field) or the (2) password parameter. NOTE: some of these details are obtained from third party information.