Ajauction
Vendor:
First CVE: Mar 7, 2007 · Active for 19 years
8
Total CVEs
Bottom 1%
2.7
Avg CVEs / Year
Bottom 1%
7.1
Avg CVSS
Higher Avg CVSS than 52% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ajauction over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 7, 2007
19 years ago
Most Recent CVE
Aug 13, 2009
6,193 days ago
CVE Severity & Scoring
Ajauction8 CVEs
13%
88%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6965HIGH AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote att | Aug 13, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6966HIGH AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass authentication via a direct request | Aug 13, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6414HIGH SQL injection vulnerability in detail.php in AJ Auction Pro Platinum Skin 2 allows remote attackers to execute arbitrary SQL commands via the item_id parameter. | Mar 6, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6003HIGH SQL injection vulnerability in sellers_othersitem.php in AJ Auction Pro Platinum 2 allows remote attackers to execute arbitrary SQL commands via the seller_id parameter. | Jan 28, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-5212HIGH SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the item_id parameter. | Nov 24, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-2860HIGH SQL injection vulnerability in category.php in AJSquare AJ Auction Pro web 2.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter. | Jun 25, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-1298HIGH SQL injection vulnerability in subcat.php in AJ Auction 1.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter. | Mar 7, 2007 | 7.5 | 28 | NO | YES |
CVE-2008-6004MEDIUM Cross-site scripting (XSS) vulnerability in search.php in AJ Auction Pro Platinum 2 allows remote attackers to inject arbitrary web script or HTML via the product parameter. | Jan 28, 2009 | 4.3 | 21 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
100.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Ajauction
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| web_2.0 | 3 | 7.5 | 1.4% | 0 | 3 |
| 2.0 | 4 | 6.7 | 1.4% | 0 | 4 |
| 1.0 | 4 | 7.5 | 1.8% | 0 | 4 |