maarch records
8 published records for vendor maarch.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 12.5%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2015-1587Weaponized | Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote atmaarch · gec\/ged | High7.5 | — | 44.2% | Feb 19, 2015 |
36Monitor | CVE-2019-15855No exploit | An issue was discovered in Maarch RM before 2.5.maarch · maarch rm · CWE-22 | Critical9.1 | — | 1.5% | Jan 17, 2020 |
35Monitor | CVE-2019-15854No exploit | An issue was discovered in Maarch RM before 2.5.maarch · maarch rm | High8.8 | — | 1.3% | Jan 17, 2020 |
30Monitor | CVE-2022-37772No exploit | Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the amaarch · maarch rm · CWE-307 | High7.5 | — | 1.2% | Nov 22, 2022 |
26Monitor | CVE-2022-37773No exploit | An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allowmaarch · maarch rm · CWE-89 | Medium6.5 | — | 0.8% | Nov 22, 2022 |
21Monitor | CVE-2014-8995Proof of concept | SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie.maarch · letterbox · CWE-89 | Medium5.0 | — | 2.2% | Nov 20, 2014 |
21Monitor | CVE-2022-37774No exploit | There is a broken access control vulnerability in the Maarch RM 2.8.3 solution.maarch · maarch rm · CWE-287 | Medium5.3 | — | 0.6% | Nov 22, 2022 |
16Monitor | CVE-2006-5492No exploit | Unspecified vulnerability in Maerys Archive (Maarch) before 2.0.1 allows remote authenticated users to obtain sensitive information (documenmaarch · maarch | Medium4.0 | — | 1.2% | Oct 25, 2006 |
- CVE-2015-158743Plan
Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote at
HighCVSS 7.5WeaponizedEPSS 44%maarch · gec\/gedFeb 19, 2015
- CVE-2019-1585536Monitor
An issue was discovered in Maarch RM before 2.5.
CriticalCVSS 9.1No exploitEPSS 2%maarch · maarch rmJan 17, 2020
- CVE-2019-1585435Monitor
An issue was discovered in Maarch RM before 2.5.
HighCVSS 8.8No exploitEPSS 1%maarch · maarch rmJan 17, 2020
- CVE-2022-3777230Monitor
Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the a
HighCVSS 7.5No exploitEPSS 1%maarch · maarch rmNov 22, 2022
- CVE-2022-3777326Monitor
An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allow
MediumCVSS 6.5No exploitEPSS 1%maarch · maarch rmNov 22, 2022
- CVE-2014-899521Monitor
SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie.
MediumCVSS 5.0Proof of conceptEPSS 2%maarch · letterboxNov 20, 2014
- CVE-2022-3777421Monitor
There is a broken access control vulnerability in the Maarch RM 2.8.3 solution.
MediumCVSS 5.3No exploitEPSS 1%maarch · maarch rmNov 22, 2022
- CVE-2006-549216Monitor
Unspecified vulnerability in Maerys Archive (Maarch) before 2.0.1 allows remote authenticated users to obtain sensitive information (documen
MediumCVSS 4.0No exploitEPSS 1%maarch · maarchOct 25, 2006