Mhproducts maintains a small portfolio of web-based business and marketplace applications—including auction, e-commerce, classified listings, and real estate platforms—that expose user-facing input surfaces vulnerable to SQL injection. The vendor's disclosures center on improper neutralization of SQL command elements, a recurring weakness class in database-driven web applications, and this weakness class has frequently acquired public exploit tooling. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mhproducts over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4847HIGH SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | Sep 27, 2011 | 7.5 | 33 | NO | YES |
CVE-2010-4846HIGH SQL injection vulnerability in view_item.php in MH Products Pay Pal Shop Digital allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | Sep 27, 2011 | 7.5 | 33 | NO | YES |
CVE-2010-5062HIGH SQL injection vulnerability in search.php in MH Products kleinanzeigenmarkt allows remote attackers to execute arbitrary SQL commands via the c parameter. | Nov 23, 2011 | 7.5 | 32 | NO | YES |
CVE-2010-4845HIGH Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the | Sep 27, 2011 | 7.5 | 32 | NO | YES |
CVE-2010-4844HIGH SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary SQL commands via the kat parameter. | Sep 27, 2011 | 7.5 | 32 | NO | YES |
CVE-2010-4721HIGH SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the id parameter. | Feb 1, 2011 | 7.5 | 32 | NO | YES |
CVE-2010-4842HIGH SQL injection vulnerability in admin/login.php in MHP DownloadScript (aka MH Products Download Center) 2.2 allows remote attackers to execute arbitrary SQL commands via the Name pa | Sep 27, 2011 | 7.5 | 31 | NO | YES |
CVE-2010-4614HIGH SQL injection vulnerability in item.php in Ero Auktion 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-0723. | Dec 29, 2010 | 7.5 | 31 | NO | YES |
CVE-2010-0723HIGH SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Feb 26, 2010 | 7.5 | 28 | NO | YES |
CVE-2010-0722HIGH SQL injection vulnerability in news.php in Php Auktion Pro allows remote attackers to execute arbitrary SQL commands via the id parameter. | Feb 26, 2010 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mhproducts.
Media articles that mention a CVE ID that affects a product developed by Mhproducts — matched by CVE ID, not by vendor name.