Vulnerabilities (CVE)

Filtered by vendor Mhproducts Subscribe
Total 9 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2010-4614 1 Mhproducts 1 Ero Auktion 2023-12-10 7.5 HIGH N/A
SQL injection vulnerability in item.php in Ero Auktion 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-0723.
CVE-2010-4844 1 Mhproducts 1 Easy Online Shop 2023-12-10 7.5 HIGH N/A
SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary SQL commands via the kat parameter.
CVE-2010-4721 1 Mhproducts 1 Immo Makler 2023-12-10 7.5 HIGH N/A
SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2010-4845 1 Mhproducts 1 Projekt Shop 2023-12-10 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php.
CVE-2010-0722 1 Mhproducts 1 Php Auktion Pro 2023-12-10 7.5 HIGH N/A
SQL injection vulnerability in news.php in Php Auktion Pro allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2010-4846 1 Mhproducts 1 Pay Pal Shop Digital 2023-12-10 7.5 HIGH N/A
SQL injection vulnerability in view_item.php in MH Products Pay Pal Shop Digital allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
CVE-2010-4842 1 Mhproducts 1 Download Center 2023-12-10 7.5 HIGH N/A
SQL injection vulnerability in admin/login.php in MHP DownloadScript (aka MH Products Download Center) 2.2 allows remote attackers to execute arbitrary SQL commands via the Name parameter. NOTE: some of these details are obtained from third party information.
CVE-2010-4847 1 Mhproducts 1 Mhp Downloadshop 2023-12-10 7.5 HIGH N/A
SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
CVE-2010-0723 1 Mhproducts 1 Ero Auktion 2023-12-10 7.5 HIGH N/A
SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.