Products: 6
    Vulnerabilities: 9
    Known Exploited: 0
    0
    Critical Level Threats
    6
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2012-4061

    Multiple SQL injection vulnerabilities in ASP-DEv XM Diary allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to diary_view.asp or (2) view_date parameter to default.asp.

    Last Modified: Apr 11, 2025
    Published: Jul 25, 2012

    CVE-2012-4060

    Multiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) profile.asp, (2) forum.asp, or (3) topic.asp.

    Last Modified: Apr 11, 2025
    Published: Jul 25, 2012

    CVE-2008-5923

    SQL injection vulnerability in default.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands the cat parameter.

    Last Modified: Apr 23, 2026
    Published: Jan 21, 2009

    CVE-2008-5925

    ASP-DEv XM Events Diary stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for diary.mdb.

    Last Modified: Apr 23, 2026
    Published: Jan 21, 2009

    CVE-2008-5926

    Multiple SQL injection vulnerabilities in login.asp in ASP-DEv Internal E-Mail System allow remote attackers to execute arbitrary SQL commands via the (1) login parameter (aka user field) or the (2) password parameter (aka pass field). NOTE: some of these details are obtained from third party information.

    Last Modified: Apr 23, 2026
    Published: Jan 21, 2009
    Items Per Page