Ajsquare's vulnerability profile centers on a narrow set of web-based e-commerce and content-management products, including its auction platforms, article systems, and polling scripts, which carry a cumulative exposure to common web-application weaknesses. Its disclosures recur through input-handling flaws—SQL injection, cross-site scripting, improper authentication, and sensitive-information exposure—that are characteristic of PHP-based or legacy web applications, and frequently acquire public exploit code. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ajsquare over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1876HIGH SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding actio | May 12, 2010 | 7.5 | 32 | NO | YES |
CVE-2010-2916HIGH SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jul 30, 2010 | 7.5 | 31 | NO | YES |
CVE-2008-2532HIGH SQL injection vulnerability in forum/topic_detail.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jun 3, 2008 | 7.5 | 31 | NO | YES |
CVE-2010-2915HIGH SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jul 30, 2010 | 7.5 | 29 | NO | YES |
CVE-2008-7051HIGH AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesusp | Aug 24, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-7041HIGH AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php. | Aug 24, 2009 | 7.5 | 29 | NO | YES |
CVE-2008-6965HIGH AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote att | Aug 13, 2009 | 7.5 | 29 | NO | YES |
CVE-2009-3203HIGH SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter. | Sep 16, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-7044HIGH SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to execute arbitrary SQL commands via th | Aug 24, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-2779HIGH SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in a productdetail action. | Aug 17, 2009 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ajsquare.
Media articles that mention a CVE ID that affects a product developed by Ajsquare — matched by CVE ID, not by vendor name.