Activewebsoftwares maintains a focused portfolio of web-based business and e-commerce applications including bidding platforms, pricing tools, business directories, and webmail systems, which occupy a notable niche in the vulnerability landscape despite a small product count. The vendor's disclosures center durably on application-layer input-handling and output-encoding weaknesses—SQL injection, cross-site scripting, and sensitive information exposure—that are characteristic of web applications built without memory-safety constraints. The vulnerability set shows a strong tendency toward public exploit availability, reflecting the straightforward attack surface and tooling maturity of web-application flaws in general. Defenders should treat this vendor's advisories as relevant to web-application exposure tiers and apply input-validation and output-encoding hardening across dependent systems; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Activewebsoftwares over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2359HIGH SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different v | Jun 21, 2010 | 7.5 | 32 | NO | YES |
CVE-2008-5975HIGH SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the linkid parameter. NOTE: the provenance of | Jan 27, 2009 | 7.5 | 29 | NO | YES |
CVE-2005-1029HIGH Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to d | Apr 6, 2005 | 7.5 | 29 | NO | YES |
CVE-2009-4437HIGH Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to wishlist.asp and the (2) | Dec 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-4436HIGH Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2 | Dec 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-4229HIGH Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter in the PATH_INFO to th | Dec 8, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6889HIGH SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter. | Aug 3, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6873HIGH SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) address | Jul 23, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6387MEDIUM Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct | Mar 2, 2009 | 5.0 | 28 | NO | YES |
CVE-2008-6380HIGH SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter. | Mar 2, 2009 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Activewebsoftwares.
Media articles that mention a CVE ID that affects a product developed by Activewebsoftwares — matched by CVE ID, not by vendor name.