Enthrallweb

    Dashboard / Vendors

    Products: 12
    Vulnerabilities: 15
    Known Exploited: 0
    0
    Critical Level Threats
    11
    High Level Threats
    1
    Medium Level Threats
    3
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2009-0252

    Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (2) Password parameter (aka password field). NOTE: some of these details are obtained from third party information.

    Last Modified: Apr 23, 2026
    Published: Jan 22, 2009

    CVE-2006-6821

    myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.

    Last Modified: Apr 23, 2026
    Published: Dec 29, 2006

    CVE-2006-6822

    myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.

    Last Modified: Apr 23, 2026
    Published: Dec 29, 2006

    CVE-2006-6820

    myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.

    Last Modified: Apr 23, 2026
    Published: Dec 29, 2006

    CVE-2006-6806

    SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Last Modified: Apr 23, 2026
    Published: Dec 28, 2006
    Items Per Page
    Enthrallweb Vulnerabilities & Security CVEs | CVE-DB