Enthrallweb maintains a portfolio of small-business web applications spanning classifieds, real estate, e-commerce, and coupon platforms, where vulnerabilities recur predominantly around SQL injection and related input-handling flaws in web-facing interfaces. The vendor's disclosures frequently acquire public exploit code, reflecting the accessibility of web-application targets and the maturity of injection-attack tooling. Defenders deploying these applications should prioritize input validation and prepared-statement enforcement across the product line; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Enthrallweb over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3027HIGH Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) CAT_ID parameter in (a) subphoto | Jun 15, 2006 | 7.5 | 29 | NO | YES |
CVE-2009-0252HIGH Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka usernam | Jan 22, 2009 | 7.5 | 28 | NO | YES |
CVE-2006-6802HIGH SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL commands via the Biz_ID parameter. | Dec 28, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6803HIGH SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL commands via the Type_id parameter. | Dec 28, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6804HIGH SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01.12 and earlier allows remote attackers | Dec 28, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6805HIGH SQL injection vulnerability in newsdetail.asp in Enthrallweb eJobs allows remote attackers to execute arbitrary SQL commands via the ID parameter. | Dec 28, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6806HIGH SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | Dec 28, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6204HIGH Multiple SQL injection vulnerabilities in Enthrallweb eHomes allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to (a) dircat.asp; the (2) sid param | Dec 1, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6208HIGH Multiple SQL injection vulnerabilities in Enthrallweb eClassifieds allow remote attackers to execute arbitrary SQL commands via the (1) AD_ID, (2) cat_id, (3) sub_id, and (4) ad_id | Dec 1, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6205MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in result.asp in Enthrallweb eHomes allow remote attackers to inject arbitrary web script or HTML via the (1) city or (2) State | Dec 1, 2006 | 6.8 | 27 | NO | YES |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Enthrallweb.
Media articles that mention a CVE ID that affects a product developed by Enthrallweb — matched by CVE ID, not by vendor name.