Aewebworks maintains a focused product portfolio centered on its aedating web application, a narrowly scoped but notable target in the landscape. The vendor's vulnerabilities frequently acquire public exploit code, making disclosures around this product a patching concern for deployments. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aewebworks over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4870HIGH Multiple PHP remote file inclusion vulnerabilities in AEDating 4.1, and possibly earlier versions, allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] pa | Sep 19, 2006 | 7.5 | 32 | NO | YES |
CVE-2005-2985HIGH SQL injection vulnerability in search_result.php in AEwebworks aeDating Script 4.0 and earlier allows remote attackers to execute arbitrary SQL statements via the Country parameter | Sep 20, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-1084HIGH SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter. | May 2, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-1083MEDIUM index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter. | May 2, 2005 | 5.0 | 15 | NO | NO |
CVE-2006-3279MEDIUM Cross-site scripting (XSS) vulnerability in aeDating 4.1 allows remote attackers to inject arbitrary web script or HTML via the (1) Sex parameter in index.php, (2) ProfileType para | Jun 28, 2006 | 4.3 | 14 | NO | NO |
CVE-2005-1085MEDIUM Cross-site scripting (XSS) vulnerability in the control panel in aeDating 3.2 allows remote attackers to inject arbitrary web script or HTML. | May 2, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aewebworks.
Media articles that mention a CVE ID that affects a product developed by Aewebworks — matched by CVE ID, not by vendor name.