Ecava kayıtları
ecava üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-310 Cryptographic Issues1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2010-4597Kavram kanıtı | Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Intecava · integraxor · CWE-119 | Kritik10,0 | — | %18,8 | 23 Ara 2010 |
40Planlayın | CVE-2017-6050İstismar yok | A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior.ecava · integraxor · CWE-89 | Kritik9,8 | — | %3,5 | 21 Haz 2017 |
39İzleyin | CVE-2012-0246İstismar yok | Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute ecava · integraxor · CWE-22 | Kritik9,3 | — | %5,9 | 2 Nis 2012 |
39İzleyin | CVE-2016-8341İstismar yok | An issue was discovered in Ecava IntegraXor Version 5.0.413.0.ecava · integraxor · CWE-89 | Kritik9,8 | — | %1,7 | 13 Şub 2017 |
38İzleyin | CVE-2012-4700İstismar yok | Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attackecava · integraxor · CWE-119 | Kritik9,3 | — | %3,8 | 8 Şub 2013 |
37İzleyin | CVE-2014-2375İstismar yok | Ecava IntegraXor SCADA Server External Control of File Name or Pathecava · integraxor · CWE-73 | Kritik9,0 | — | %2,3 | 15 Eyl 2014 |
32İzleyin | CVE-2014-0753İstismar yok | Ecava IntegraXor Stack-based Buffer Overflowecava · integraxor · CWE-121 | Yüksek7,8 | — | %2,5 | 20 Oca 2014 |
31İzleyin | CVE-2014-2376İstismar yok | Ecava IntegraXor SCADA Server SQL Injectionecava · integraxor · CWE-89 | Yüksek7,5 | — | %2,0 | 15 Eyl 2014 |
31İzleyin | CVE-2016-2306İstismar yok | The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing tecava · integraxor · CWE-310 | Yüksek7,5 | — | %1,9 | 21 Nis 2016 |
31İzleyin | CVE-2011-1562İstismar yok | Ecava IntegraXor HMI before n 3.60 (Build 4032) allows remote attackers to bypass authentication and execute arbitrary SQL statements via unecava · integraxor · CWE-89 | Yüksek7,5 | — | %1,7 | 5 Nis 2011 |
29İzleyin | CVE-2016-2299İstismar yok | SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecifecava · integraxor · CWE-89 | Yüksek7,3 | — | %1,4 | 21 Nis 2016 |
28İzleyin | CVE-2010-4598Kavram kanıtı | Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a ..ecava · integraxor · CWE-22 | Orta5,0 | — | %26,5 | 23 Ara 2010 |
27İzleyin | CVE-2010-4599İstismar yok | Untrusted search path vulnerability in Ecava IntegraXor 3.6.4000.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file ecava · integraxor | Orta6,9 | — | %0,3 | 23 Ara 2010 |
26İzleyin | CVE-2016-2300İstismar yok | Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectorsecava · integraxor · CWE-287 | Orta6,5 | — | %1,2 | 21 Nis 2016 |
25İzleyin | CVE-2016-2301İstismar yok | SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbitrary SQL commands viecava · integraxor · CWE-89 | Orta6,3 | — | %0,8 | 21 Nis 2016 |
24İzleyin | CVE-2016-2305İstismar yok | Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary web script orecava · integraxor · CWE-79 | Orta6,1 | — | %0,9 | 21 Nis 2016 |
21İzleyin | CVE-2014-0786İstismar yok | Ecava IntegraXor Information Exposureecava · integraxor · CWE-200 | Orta5,0 | — | %2,7 | 30 Nis 2014 |
21İzleyin | CVE-2014-2377İstismar yok | Ecava IntegraXor SCADA Server Information Exposure Through Environmental Variablesecava · integraxor · CWE-526 | Orta5,0 | — | %1,8 | 15 Eyl 2014 |
21İzleyin | CVE-2016-2302İstismar yok | Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.ecava · integraxor · CWE-200 | Orta5,3 | — | %1,2 | 21 Nis 2016 |
21İzleyin | CVE-2016-2303İstismar yok | CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP headers and conduct ecava · integraxor | Orta5,3 | — | %1,1 | 21 Nis 2016 |
21İzleyin | CVE-2017-16735İstismar yok | A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior.ecava · integraxor · CWE-89 | Orta5,3 | — | %1,0 | 20 Ara 2017 |
21İzleyin | CVE-2017-16733İstismar yok | A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior.ecava · integraxor · CWE-89 | Orta5,3 | — | %0,9 | 20 Ara 2017 |
20İzleyin | CVE-2014-0752İstismar yok | Ecava IntegraXor Exposure of Access Control List Files to an Unauthorized Control Sphereecava · integraxor · CWE-529 | Orta5,0 | — | %1,6 | 9 Oca 2014 |
17İzleyin | CVE-2011-2958İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Ecava IntegraXor before 3.60 (Build 4080) allow remote attackers to inject arbitrary ecava · integraxor · CWE-79 | Orta4,3 | — | %1,2 | 28 Tem 2011 |
17İzleyin | CVE-2016-2304İstismar yok | Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easiecava · integraxor · CWE-200 | Orta4,3 | — | %1,1 | 21 Nis 2016 |
- CVE-2010-459746Planlayın
Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Int
KritikCVSS 10,0Kavram kanıtıEPSS %19ecava · integraxor23 Ara 2010
- CVE-2017-605040Planlayın
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior.
KritikCVSS 9,8İstismar yokEPSS %4ecava · integraxor21 Haz 2017
- CVE-2012-024639İzleyin
Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute
KritikCVSS 9,3İstismar yokEPSS %6ecava · integraxor2 Nis 2012
- CVE-2016-834139İzleyin
An issue was discovered in Ecava IntegraXor Version 5.0.413.0.
KritikCVSS 9,8İstismar yokEPSS %2ecava · integraxor13 Şub 2017
- CVE-2012-470038İzleyin
Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attack
KritikCVSS 9,3İstismar yokEPSS %4ecava · integraxor8 Şub 2013
- CVE-2014-237537İzleyin
Ecava IntegraXor SCADA Server External Control of File Name or Path
KritikCVSS 9,0İstismar yokEPSS %2ecava · integraxor15 Eyl 2014
- CVE-2014-075332İzleyin
Ecava IntegraXor Stack-based Buffer Overflow
YüksekCVSS 7,8İstismar yokEPSS %3ecava · integraxor20 Oca 2014
- CVE-2014-237631İzleyin
Ecava IntegraXor SCADA Server SQL Injection
YüksekCVSS 7,5İstismar yokEPSS %2ecava · integraxor15 Eyl 2014
- CVE-2016-230631İzleyin
The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing t
YüksekCVSS 7,5İstismar yokEPSS %2ecava · integraxor21 Nis 2016
- CVE-2011-156231İzleyin
Ecava IntegraXor HMI before n 3.60 (Build 4032) allows remote attackers to bypass authentication and execute arbitrary SQL statements via un
YüksekCVSS 7,5İstismar yokEPSS %2ecava · integraxor5 Nis 2011
- CVE-2016-229929İzleyin
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecif
YüksekCVSS 7,3İstismar yokEPSS %1ecava · integraxor21 Nis 2016
- CVE-2010-459828İzleyin
Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a ..
OrtaCVSS 5,0Kavram kanıtıEPSS %26ecava · integraxor23 Ara 2010
- CVE-2010-459927İzleyin
Untrusted search path vulnerability in Ecava IntegraXor 3.6.4000.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file
OrtaCVSS 6,9İstismar yokEPSS %0ecava · integraxor23 Ara 2010
- CVE-2016-230026İzleyin
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors
OrtaCVSS 6,5İstismar yokEPSS %1ecava · integraxor21 Nis 2016
- CVE-2016-230125İzleyin
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbitrary SQL commands vi
OrtaCVSS 6,3İstismar yokEPSS %1ecava · integraxor21 Nis 2016
- CVE-2016-230524İzleyin
Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary web script or
OrtaCVSS 6,1İstismar yokEPSS %1ecava · integraxor21 Nis 2016
- CVE-2014-078621İzleyin
Ecava IntegraXor Information Exposure
OrtaCVSS 5,0İstismar yokEPSS %3ecava · integraxor30 Nis 2014
- CVE-2014-237721İzleyin
Ecava IntegraXor SCADA Server Information Exposure Through Environmental Variables
OrtaCVSS 5,0İstismar yokEPSS %2ecava · integraxor15 Eyl 2014
- CVE-2016-230221İzleyin
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.
OrtaCVSS 5,3İstismar yokEPSS %1ecava · integraxor21 Nis 2016
- CVE-2016-230321İzleyin
CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP headers and conduct
OrtaCVSS 5,3İstismar yokEPSS %1ecava · integraxor21 Nis 2016
- CVE-2017-1673521İzleyin
A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior.
OrtaCVSS 5,3İstismar yokEPSS %1ecava · integraxor20 Ara 2017
- CVE-2017-1673321İzleyin
A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior.
OrtaCVSS 5,3İstismar yokEPSS %1ecava · integraxor20 Ara 2017
- CVE-2014-075220İzleyin
Ecava IntegraXor Exposure of Access Control List Files to an Unauthorized Control Sphere
OrtaCVSS 5,0İstismar yokEPSS %2ecava · integraxor9 Oca 2014
- CVE-2011-295817İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Ecava IntegraXor before 3.60 (Build 4080) allow remote attackers to inject arbitrary
OrtaCVSS 4,3İstismar yokEPSS %1ecava · integraxor28 Tem 2011
- CVE-2016-230417İzleyin
Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easi
OrtaCVSS 4,3İstismar yokEPSS %1ecava · integraxor21 Nis 2016