arialsoftware records
5 published records for vendor arialsoftware.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-863 Incorrect Authorization2
- CWE-287 Improper Authentication1
- CWE-522 Insufficiently Protected Credentials1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2012-3820No exploit | Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to exearialsoftware · campaign enterprise · CWE-89 | High7.5 | — | 2.1% | Aug 14, 2014 |
31Monitor | CVE-2012-3822No exploit | Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate userarialsoftware · campaign enterprise · CWE-863 | High7.5 | — | 1.9% | Jan 10, 2020 |
31Monitor | CVE-2012-3824No exploit | In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.arialsoftware · campaign enterprise · CWE-287 | High7.5 | — | 1.8% | Jan 10, 2020 |
30Monitor | CVE-2012-3823No exploit | Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.arialsoftware · campaign enterprise · CWE-522 | High7.5 | — | 1.5% | Jan 10, 2020 |
17Monitor | CVE-2012-3821No exploit | A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malarialsoftware · campaign enterprise · CWE-863 | Medium4.3 | — | 1.2% | Jan 10, 2020 |
- CVE-2012-382031Monitor
Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to exe
HighCVSS 7.5No exploitEPSS 2%arialsoftware · campaign enterpriseAug 14, 2014
- CVE-2012-382231Monitor
Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate user
HighCVSS 7.5No exploitEPSS 2%arialsoftware · campaign enterpriseJan 10, 2020
- CVE-2012-382431Monitor
In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.
HighCVSS 7.5No exploitEPSS 2%arialsoftware · campaign enterpriseJan 10, 2020
- CVE-2012-382330Monitor
Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
HighCVSS 7.5No exploitEPSS 1%arialsoftware · campaign enterpriseJan 10, 2020
- CVE-2012-382117Monitor
A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote mal
MediumCVSS 4.3No exploitEPSS 1%arialsoftware · campaign enterpriseJan 10, 2020