RSS   Vulnerabilities for 'Active price comparison'   RSS

2009-01-26
 
CVE-2008-5975

CWE-89
 

 
SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the linkid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

 
 
CVE-2008-5974

CWE-89
 

 
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) username fields.

 
2008-12-17
 
CVE-2008-5638

CWE-89
 

 
Multiple SQL injection vulnerabilities in Active Price Comparison 4 allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter to reviews.aspx or the (2) linkid parameter to links.asp.

 

 >>> Vendor: Activewebsoftwares 18 Products
Activevotes
Active trade
Active ewebquiz
Active time billing
Active force matrix
Active membership
Active price comparison
Active bids
Active photo gallery
Active test
Active business directory
Active web mail
Active newsletter
Active web helpdesk
Quick tree view .net
Aspreferral
Ewebquiz
Active auction house


Copyright 2017, cxsecurity.com