Aggregates CVE and security vulnerability intelligence across all mhproducts-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Common weakness patterns include vendor risk sql injection, with potential vendor impact data exposure across vendor surface software deployment and vendor surface production workloads use cases.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2010-4847 | SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | [email protected] | 7.5 | 1.14% | 2011-09-27 | 2026-04-29 |
| CVE-2010-4846 | SQL injection vulnerability in view_item.php in MH Products Pay Pal Shop Digital allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | [email protected] | 7.5 | 0.14% | 2011-09-27 | 2026-04-29 |
| CVE-2010-4845 | Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php. | [email protected] | 7.5 | 0.14% | 2011-09-27 | 2026-04-29 |
| CVE-2010-4844 | SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary SQL commands via the kat parameter. | [email protected] | 7.5 | 1.61% | 2011-09-27 | 2026-04-29 |
| CVE-2010-4842 | SQL injection vulnerability in admin/login.php in MHP DownloadScript (aka MH Products Download Center) 2.2 allows remote attackers to execute arbitrary SQL commands via the Name parameter. NOTE: some of these details are obtained from third party information. | [email protected] | 7.5 | 0.24% | 2011-09-27 | 2026-04-29 |
| CVE-2010-4721 | SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the id parameter. | [email protected] | 7.5 | 1.60% | 2011-02-01 | 2026-04-29 |
| CVE-2010-4614 | SQL injection vulnerability in item.php in Ero Auktion 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-0723. | [email protected] | 7.5 | 0.42% | 2010-12-29 | 2026-04-29 |
| CVE-2010-0723 | SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter. | [email protected] | 7.5 | 1.91% | 2010-02-26 | 2026-04-29 |
| CVE-2010-0722 | SQL injection vulnerability in news.php in Php Auktion Pro allows remote attackers to execute arbitrary SQL commands via the id parameter. | [email protected] | 7.5 | 0.28% | 2010-02-26 | 2026-04-29 |