Mh Products operates a small-scale online classifieds platform, Kleinanzeigenmarkt, where its vulnerability profile centers on application-layer input handling. The recurring exposure reflects SQL injection weaknesses characteristic of web-facing marketplace services that process user-supplied search and listing data. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mh Products over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4847HIGH SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | Sep 27, 2011 | 7.5 | 33 | NO | YES |
CVE-2010-4846HIGH SQL injection vulnerability in view_item.php in MH Products Pay Pal Shop Digital allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | Sep 27, 2011 | 7.5 | 33 | NO | YES |
CVE-2010-5062HIGH SQL injection vulnerability in search.php in MH Products kleinanzeigenmarkt allows remote attackers to execute arbitrary SQL commands via the c parameter. | Nov 23, 2011 | 7.5 | 32 | NO | YES |
CVE-2010-4845HIGH Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the | Sep 27, 2011 | 7.5 | 32 | NO | YES |
CVE-2010-4844HIGH SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary SQL commands via the kat parameter. | Sep 27, 2011 | 7.5 | 32 | NO | YES |
CVE-2010-4721HIGH SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the id parameter. | Feb 1, 2011 | 7.5 | 32 | NO | YES |
CVE-2010-4842HIGH SQL injection vulnerability in admin/login.php in MHP DownloadScript (aka MH Products Download Center) 2.2 allows remote attackers to execute arbitrary SQL commands via the Name pa | Sep 27, 2011 | 7.5 | 31 | NO | YES |
CVE-2010-4614HIGH SQL injection vulnerability in item.php in Ero Auktion 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-0723. | Dec 29, 2010 | 7.5 | 31 | NO | YES |
CVE-2010-0723HIGH SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Feb 26, 2010 | 7.5 | 28 | NO | YES |
CVE-2010-0722HIGH SQL injection vulnerability in news.php in Php Auktion Pro allows remote attackers to execute arbitrary SQL commands via the id parameter. | Feb 26, 2010 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mh Products.
Media articles that mention a CVE ID that affects a product developed by Mh Products — matched by CVE ID, not by vendor name.