Digiappz develops a focused suite of business-application and productivity software including affiliate management, reservation, domain administration, and leave-management tools. The vendor's vulnerability profile centers on application-layer input-handling defects, with SQL injection and cross-site scripting forming the recurring weak points across its product line, indicating insufficient input validation and output encoding in web-facing modules. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Digiappz over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3309HIGH SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter. | Jul 25, 2008 | 7.5 | 33 | NO | YES |
CVE-2008-6487HIGH Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin and (2) pas | Mar 18, 2009 | 7.5 | 28 | NO | YES |
CVE-2007-0306HIGH SQL injection vulnerability in visu_user.asp in Digiappz DigiAffiliate 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jan 18, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-0128HIGH SQL injection vulnerability in info_book.asp in Digirez 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter. | Jan 9, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-4524HIGH Multiple SQL injection vulnerabilities in login_verif.asp in Digiappz Freekot 1.01 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) password parame | Sep 1, 2006 | 7.5 | 28 | NO | YES |
CVE-2008-1560MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Digiappz DigiDomain 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) domain parameter to lookup_ | Mar 31, 2008 | 4.3 | 21 | NO | YES |
CVE-2007-2880MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Digirez 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Room_name parameter to room/info_book.a | May 29, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Digiappz.
Media articles that mention a CVE ID that affects a product developed by Digiappz — matched by CVE ID, not by vendor name.