Active Web Softwares maintains a portfolio of e-commerce and content-management applications including auction platforms, shopping carts, link engines, newsletters, and photo galleries, with a niche but stable presence in the vulnerability landscape. The recurring signal across these products centers on SQL injection vulnerabilities, reflecting the input-handling demands of database-driven web applications, and public exploit code has frequently become available for disclosed flaws in this vendor's software. Defenders using these legacy web applications should prioritize SQL injection patching and input validation hardening; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Active Web Softwares over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2359HIGH SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different v | Jun 21, 2010 | 7.5 | 32 | NO | YES |
CVE-2008-5975HIGH SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the linkid parameter. NOTE: the provenance of | Jan 27, 2009 | 7.5 | 29 | NO | YES |
CVE-2005-1029HIGH Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to d | Apr 6, 2005 | 7.5 | 29 | NO | YES |
CVE-2009-4437HIGH Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to wishlist.asp and the (2) | Dec 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-4436HIGH Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2 | Dec 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-4229HIGH Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter in the PATH_INFO to th | Dec 8, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6889HIGH SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter. | Aug 3, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6873HIGH SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) address | Jul 23, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6387MEDIUM Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct | Mar 2, 2009 | 5.0 | 28 | NO | YES |
CVE-2008-6380HIGH SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter. | Mar 2, 2009 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Active Web Softwares.
Media articles that mention a CVE ID that affects a product developed by Active Web Softwares — matched by CVE ID, not by vendor name.