iii records
6 published records for vendor iii.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2014-2081Proof of concept | Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua before 2013.2.4 and 201iii · vtls-virtua · CWE-89 | High7.5 | — | 2.1% | Oct 20, 2014 |
30Monitor | CVE-2014-5138No exploit | Innovative Interfaces Sierra Library Services Platform 1.2_3 does not properly handle query strings with multiple instances of the same paraiii · sierra | High7.5 | — | 1.6% | Jan 14, 2020 |
24Monitor | CVE-2014-5127No exploit | Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect users to arbitrary weiii · encore discovery solution | Medium5.8 | — | 2.1% | Aug 29, 2014 |
21Monitor | CVE-2014-5128No exploit | Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitiviii · encore discovery solution · CWE-200 | Medium5.0 | — | 2.3% | Aug 29, 2014 |
20Monitor | CVE-2014-5137No exploit | Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user aciii · sierra · CWE-200 | Medium5.0 | — | 1.2% | Sep 2, 2014 |
17Monitor | CVE-2014-5136No exploit | Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject aiii · sierra · CWE-79 | Medium4.3 | — | 0.9% | Sep 2, 2014 |
- CVE-2014-208131Monitor
Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua before 2013.2.4 and 201
HighCVSS 7.5Proof of conceptEPSS 2%iii · vtls-virtuaOct 20, 2014
- CVE-2014-513830Monitor
Innovative Interfaces Sierra Library Services Platform 1.2_3 does not properly handle query strings with multiple instances of the same para
HighCVSS 7.5No exploitEPSS 2%iii · sierraJan 14, 2020
- CVE-2014-512724Monitor
Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect users to arbitrary we
MediumCVSS 5.8No exploitEPSS 2%iii · encore discovery solutionAug 29, 2014
- CVE-2014-512821Monitor
Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitiv
MediumCVSS 5.0No exploitEPSS 2%iii · encore discovery solutionAug 29, 2014
- CVE-2014-513720Monitor
Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user ac
MediumCVSS 5.0No exploitEPSS 1%iii · sierraSep 2, 2014
- CVE-2014-513617Monitor
Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject a
MediumCVSS 4.3No exploitEPSS 1%iii · sierraSep 2, 2014