Aggregates CVE and security vulnerability intelligence across all dmxready-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk sql injection and vendor risk cross-site scripting and related security problems, affecting vendor surface production workloads and vendor surface software deployment scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2010-4921 | SQL injection vulnerability in inc_pollingboothmanager.asp in DMXReady Polling Booth Manager allows remote attackers to execute arbitrary SQL commands via the QuestionID parameter in a results action. | [email protected] | 7.5 | 1.85% | 2011-10-08 | 2026-04-29 |
| CVE-2010-2342 | SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | [email protected] | 7.5 | 0.23% | 2010-06-21 | 2026-04-29 |
| CVE-2009-2238 | Unrestricted file upload vulnerability in includes/shared_scripts/wysiwyg_editor/assetmanager/assetmanager.asp in DMXReady Registration Manager 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in assets/webblogmanager. | [email protected] | 6.8 | 3.30% | 2009-06-27 | 2026-04-23 |
| CVE-2009-1821 | DMXReady Registration Manager 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for databases/webblogmanager.mdb. | [email protected] | 5.0 | 5.37% | 2009-05-29 | 2026-04-23 |
| CVE-2009-0454 | Multiple SQL injection vulnerabilities in DMXReady Online Notebook Manager 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field. NOTE: some third parties report inability to verify this issue. | [email protected] | 7.5 | 0.53% | 2009-02-10 | 2026-04-23 |
| CVE-2009-0428 | SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Secure Document Library 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | [email protected] | 7.5 | 1.67% | 2009-02-05 | 2026-04-23 |
| CVE-2009-0427 | SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | [email protected] | 7.5 | 1.67% | 2009-02-05 | 2026-04-23 |
| CVE-2009-0426 | SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | [email protected] | 7.5 | 0.48% | 2009-02-05 | 2026-04-23 |
| CVE-2009-0339 | SQL injection vulnerability in inc_webblogmanager.asp in DMXReady Blog Manager allows remote attackers to execute arbitrary SQL commands via the itemID parameter in a view action. | [email protected] | 7.5 | 0.47% | 2009-01-29 | 2026-04-23 |
| CVE-2009-0338 | Cross-site scripting (XSS) vulnerability in inc_webblogmanager.asp in DMXReady Blog Manager allows remote attackers to inject arbitrary web script or HTML via the CategoryID parameter in a refer action. | [email protected] | 4.3 | 2.66% | 2009-01-29 | 2026-04-23 |
| CVE-2006-7118 | SQL injection vulnerability in index.asp in DMXReady Site Engine Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter. | [email protected] | 7.5 | 0.81% | 2007-03-06 | 2026-04-23 |
| CVE-2006-6816 | Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) set_preferences.asp, (2) send_password_preferences.asp, and (3) SecureLoginManager/list.asp in the Local-Admin Panel; (4) the sent parameter to (a) login.asp, (b) content.asp, and (c) members.asp in the Remote-WebSite; and (5) the sent parameter to applications/SecureLoginManager/inc_secureloginmanager.asp in the Live Demo. | [email protected] | 7.5 | 2.93% | 2006-12-29 | 2026-04-23 |
| CVE-2006-6815 | Multiple cross-site scripting (XSS) vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified parameters to (1) set_preferences.asp, (2) send_password_preferences.asp, and (3) SecureLoginManager/list.asp in the Local-Admin Panel. | [email protected] | 6.0 | 0.80% | 2006-12-29 | 2026-04-23 |
| CVE-2004-2189 | SQL injection vulnerability in DMXReady Site Chassis Manager allows remote attackers to execute arbitrary SQL commands via unknown vectors. | [email protected] | 7.5 | 0.43% | 2004-12-31 | 2026-04-16 |
| CVE-2004-2188 | Cross-site scripting (XSS) vulnerability in DMXReady Site Chassis Manager allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | [email protected] | 4.3 | 0.34% | 2004-12-31 | 2026-04-16 |