Alan Ward's vulnerability profile centers on a narrow set of web application products, primarily A-Cart and A-FAQ, which appear to serve e-commerce and content-management functions. While the observed weakness classifications are generic placeholders in the public record, the product line's web-facing nature and application-layer exposure merit baseline monitoring. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alan Ward over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6831HIGH SQL injection vulnerability in faqDsp.asp in aFAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the catcode parameter. | Dec 31, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6111HIGH Multiple SQL injection vulnerabilities in Alan Ward A-Cart Pro 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) productid parameter in product.asp or (2) se | Nov 26, 2006 | 7.5 | 28 | NO | YES |
CVE-2005-4064HIGH Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) faqid parameter to faqDspItem.asp and (2) catcode parameter | Dec 7, 2005 | 7.5 | 28 | NO | YES |
CVE-2004-1873HIGH SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via the catcode parameter. | Dec 31, 2004 | 7.5 | 28 | NO | YES |
CVE-2006-2948MEDIUM A-CART 2.0 stores the acart2_0.mdb file under the web document root with insufficient access control, which allows remote attackers to obtain username and password information. | Jun 12, 2006 | 5.0 | 15 | NO | NO |
CVE-2004-1874MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in (1) deliver.asp and (2) billing.asp in A-CART Pro and A-CART 2.0 allow remote attackers to inject arbitrary web script or HTM | Mar 29, 2004 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alan Ward.
Media articles that mention a CVE ID that affects a product developed by Alan Ward — matched by CVE ID, not by vendor name.