Записи arialsoftware
5 опубликованных записей вендора arialsoftware.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-863 Incorrect Authorization2
- CWE-287 Improper Authentication1
- CWE-522 Insufficiently Protected Credentials1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2012-3820Эксплойта нет | Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to exearialsoftware · campaign enterprise · CWE-89 | Высокая7,5 | — | 2,1 % | 14 авг. 2014 г. |
31Наблюдать | CVE-2012-3822Эксплойта нет | Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate userarialsoftware · campaign enterprise · CWE-863 | Высокая7,5 | — | 1,9 % | 10 янв. 2020 г. |
31Наблюдать | CVE-2012-3824Эксплойта нет | In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.arialsoftware · campaign enterprise · CWE-287 | Высокая7,5 | — | 1,8 % | 10 янв. 2020 г. |
30Наблюдать | CVE-2012-3823Эксплойта нет | Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.arialsoftware · campaign enterprise · CWE-522 | Высокая7,5 | — | 1,5 % | 10 янв. 2020 г. |
17Наблюдать | CVE-2012-3821Эксплойта нет | A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malarialsoftware · campaign enterprise · CWE-863 | Средняя4,3 | — | 1,2 % | 10 янв. 2020 г. |
- CVE-2012-382031Наблюдать
Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to exe
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %arialsoftware · campaign enterprise14 авг. 2014 г.
- CVE-2012-382231Наблюдать
Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate user
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %arialsoftware · campaign enterprise10 янв. 2020 г.
- CVE-2012-382431Наблюдать
In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %arialsoftware · campaign enterprise10 янв. 2020 г.
- CVE-2012-382330Наблюдать
Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %arialsoftware · campaign enterprise10 янв. 2020 г.
- CVE-2012-382117Наблюдать
A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote mal
СредняяCVSS 4,3Эксплойта нетEPSS 1 %arialsoftware · campaign enterprise10 янв. 2020 г.