Shalwan develops a focused set of applications, principally OPIAL and ZAINU, that have surfaced vulnerabilities centered on SQL injection—a class of input-handling flaw that reflects typical web-application development challenges. Treat this as a compact vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shalwan over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3310HIGH SQL injection vulnerability in index.php in Zainu 1.0 allows remote attackers to execute arbitrary SQL commands via the album_id parameter in an AlbumSongs action. | Sep 23, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-2388MEDIUM SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the txtPassword parameter. NOTE: the provenance of this i | Jul 9, 2009 | 6.8 | 28 | NO | YES |
CVE-2009-2341HIGH SQL injection vulnerability in albumdetail.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the albumid parameter. | Jul 7, 2009 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shalwan.
Media articles that mention a CVE ID that affects a product developed by Shalwan — matched by CVE ID, not by vendor name.