Aj Square develops a portfolio of web-based marketplace and content-management applications including auction, HYIP investment, article, and classified-listing platforms. The vendor's disclosures center on application-layer input-handling and authentication weaknesses—SQL injection, cross-site scripting, and improper authentication—that are characteristic of database-driven web applications and tend to acquire public exploit tooling. Current severity, in-the-wild exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aj Square over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1876HIGH SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding actio | May 12, 2010 | 7.5 | 32 | NO | YES |
CVE-2010-2916HIGH SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jul 30, 2010 | 7.5 | 31 | NO | YES |
CVE-2008-2532HIGH SQL injection vulnerability in forum/topic_detail.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jun 3, 2008 | 7.5 | 31 | NO | YES |
CVE-2010-2915HIGH SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jul 30, 2010 | 7.5 | 29 | NO | YES |
CVE-2008-7051HIGH AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesusp | Aug 24, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-7041HIGH AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php. | Aug 24, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6965HIGH AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote att | Aug 13, 2009 | 7.5 | 29 | NO | YES |
CVE-2009-3203HIGH SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter. | Sep 16, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-7044HIGH SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to execute arbitrary SQL commands via th | Aug 24, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-2779HIGH SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in a productdetail action. | Aug 17, 2009 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aj Square.
Media articles that mention a CVE ID that affects a product developed by Aj Square — matched by CVE ID, not by vendor name.