Skip to content
Noroxi

iblsoft records

3 published records for vendor iblsoft.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

3 records
  • CVE-2020-9406
    39Monitor

    IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.

    CriticalCVSS 9.8No exploitEPSS 1%

    iblsoft · online weatherFeb 25, 2020

  • CVE-2020-9405
    24Monitor

    IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page.

    MediumCVSS 6.1No exploitEPSS 1%

    iblsoft · online weatherFeb 25, 2020

  • CVE-2020-9407
    21Monitor

    IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie.

    MediumCVSS 5.3No exploitEPSS 1%

    iblsoft · online weatherFeb 25, 2020