Записи Ecava
26 опубликованных записей вендора ecava.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-310 Cryptographic Issues1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
26 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2010-4597Proof of concept | Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Intecava · integraxor · CWE-119 | Критическая10,0 | — | 18,8 % | 23 дек. 2010 г. |
40В плане | CVE-2017-6050Эксплойта нет | A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior.ecava · integraxor · CWE-89 | Критическая9,8 | — | 3,5 % | 21 июн. 2017 г. |
39Наблюдать | CVE-2012-0246Эксплойта нет | Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute ecava · integraxor · CWE-22 | Критическая9,3 | — | 5,9 % | 2 апр. 2012 г. |
39Наблюдать | CVE-2016-8341Эксплойта нет | An issue was discovered in Ecava IntegraXor Version 5.0.413.0.ecava · integraxor · CWE-89 | Критическая9,8 | — | 1,7 % | 13 февр. 2017 г. |
38Наблюдать | CVE-2012-4700Эксплойта нет | Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attackecava · integraxor · CWE-119 | Критическая9,3 | — | 3,8 % | 8 февр. 2013 г. |
37Наблюдать | CVE-2014-2375Эксплойта нет | Ecava IntegraXor SCADA Server External Control of File Name or Pathecava · integraxor · CWE-73 | Критическая9,0 | — | 2,3 % | 15 сент. 2014 г. |
32Наблюдать | CVE-2014-0753Эксплойта нет | Ecava IntegraXor Stack-based Buffer Overflowecava · integraxor · CWE-121 | Высокая7,8 | — | 2,5 % | 20 янв. 2014 г. |
31Наблюдать | CVE-2014-2376Эксплойта нет | Ecava IntegraXor SCADA Server SQL Injectionecava · integraxor · CWE-89 | Высокая7,5 | — | 2,0 % | 15 сент. 2014 г. |
31Наблюдать | CVE-2016-2306Эксплойта нет | The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing tecava · integraxor · CWE-310 | Высокая7,5 | — | 1,9 % | 21 апр. 2016 г. |
31Наблюдать | CVE-2011-1562Эксплойта нет | Ecava IntegraXor HMI before n 3.60 (Build 4032) allows remote attackers to bypass authentication and execute arbitrary SQL statements via unecava · integraxor · CWE-89 | Высокая7,5 | — | 1,7 % | 5 апр. 2011 г. |
29Наблюдать | CVE-2016-2299Эксплойта нет | SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecifecava · integraxor · CWE-89 | Высокая7,3 | — | 1,4 % | 21 апр. 2016 г. |
28Наблюдать | CVE-2010-4598Proof of concept | Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a ..ecava · integraxor · CWE-22 | Средняя5,0 | — | 26,5 % | 23 дек. 2010 г. |
27Наблюдать | CVE-2010-4599Эксплойта нет | Untrusted search path vulnerability in Ecava IntegraXor 3.6.4000.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file ecava · integraxor | Средняя6,9 | — | 0,3 % | 23 дек. 2010 г. |
26Наблюдать | CVE-2016-2300Эксплойта нет | Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectorsecava · integraxor · CWE-287 | Средняя6,5 | — | 1,2 % | 21 апр. 2016 г. |
25Наблюдать | CVE-2016-2301Эксплойта нет | SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbitrary SQL commands viecava · integraxor · CWE-89 | Средняя6,3 | — | 0,8 % | 21 апр. 2016 г. |
24Наблюдать | CVE-2016-2305Эксплойта нет | Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary web script orecava · integraxor · CWE-79 | Средняя6,1 | — | 0,9 % | 21 апр. 2016 г. |
21Наблюдать | CVE-2014-0786Эксплойта нет | Ecava IntegraXor Information Exposureecava · integraxor · CWE-200 | Средняя5,0 | — | 2,7 % | 30 апр. 2014 г. |
21Наблюдать | CVE-2014-2377Эксплойта нет | Ecava IntegraXor SCADA Server Information Exposure Through Environmental Variablesecava · integraxor · CWE-526 | Средняя5,0 | — | 1,8 % | 15 сент. 2014 г. |
21Наблюдать | CVE-2016-2302Эксплойта нет | Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.ecava · integraxor · CWE-200 | Средняя5,3 | — | 1,2 % | 21 апр. 2016 г. |
21Наблюдать | CVE-2016-2303Эксплойта нет | CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP headers and conduct ecava · integraxor | Средняя5,3 | — | 1,1 % | 21 апр. 2016 г. |
21Наблюдать | CVE-2017-16735Эксплойта нет | A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior.ecava · integraxor · CWE-89 | Средняя5,3 | — | 1,0 % | 20 дек. 2017 г. |
21Наблюдать | CVE-2017-16733Эксплойта нет | A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior.ecava · integraxor · CWE-89 | Средняя5,3 | — | 0,9 % | 20 дек. 2017 г. |
20Наблюдать | CVE-2014-0752Эксплойта нет | Ecava IntegraXor Exposure of Access Control List Files to an Unauthorized Control Sphereecava · integraxor · CWE-529 | Средняя5,0 | — | 1,6 % | 9 янв. 2014 г. |
17Наблюдать | CVE-2011-2958Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Ecava IntegraXor before 3.60 (Build 4080) allow remote attackers to inject arbitrary ecava · integraxor · CWE-79 | Средняя4,3 | — | 1,2 % | 28 июл. 2011 г. |
17Наблюдать | CVE-2016-2304Эксплойта нет | Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easiecava · integraxor · CWE-200 | Средняя4,3 | — | 1,1 % | 21 апр. 2016 г. |
- CVE-2010-459746В плане
Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Int
КритическаяCVSS 10,0Proof of conceptEPSS 19 %ecava · integraxor23 дек. 2010 г.
- CVE-2017-605040В плане
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %ecava · integraxor21 июн. 2017 г.
- CVE-2012-024639Наблюдать
Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %ecava · integraxor2 апр. 2012 г.
- CVE-2016-834139Наблюдать
An issue was discovered in Ecava IntegraXor Version 5.0.413.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ecava · integraxor13 февр. 2017 г.
- CVE-2012-470038Наблюдать
Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attack
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %ecava · integraxor8 февр. 2013 г.
- CVE-2014-237537Наблюдать
Ecava IntegraXor SCADA Server External Control of File Name or Path
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %ecava · integraxor15 сент. 2014 г.
- CVE-2014-075332Наблюдать
Ecava IntegraXor Stack-based Buffer Overflow
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %ecava · integraxor20 янв. 2014 г.
- CVE-2014-237631Наблюдать
Ecava IntegraXor SCADA Server SQL Injection
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ecava · integraxor15 сент. 2014 г.
- CVE-2016-230631Наблюдать
The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing t
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ecava · integraxor21 апр. 2016 г.
- CVE-2011-156231Наблюдать
Ecava IntegraXor HMI before n 3.60 (Build 4032) allows remote attackers to bypass authentication and execute arbitrary SQL statements via un
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ecava · integraxor5 апр. 2011 г.
- CVE-2016-229929Наблюдать
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecif
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %ecava · integraxor21 апр. 2016 г.
- CVE-2010-459828Наблюдать
Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a ..
СредняяCVSS 5,0Proof of conceptEPSS 26 %ecava · integraxor23 дек. 2010 г.
- CVE-2010-459927Наблюдать
Untrusted search path vulnerability in Ecava IntegraXor 3.6.4000.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file
СредняяCVSS 6,9Эксплойта нетEPSS 0 %ecava · integraxor23 дек. 2010 г.
- CVE-2016-230026Наблюдать
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors
СредняяCVSS 6,5Эксплойта нетEPSS 1 %ecava · integraxor21 апр. 2016 г.
- CVE-2016-230125Наблюдать
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbitrary SQL commands vi
СредняяCVSS 6,3Эксплойта нетEPSS 1 %ecava · integraxor21 апр. 2016 г.
- CVE-2016-230524Наблюдать
Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary web script or
СредняяCVSS 6,1Эксплойта нетEPSS 1 %ecava · integraxor21 апр. 2016 г.
- CVE-2014-078621Наблюдать
Ecava IntegraXor Information Exposure
СредняяCVSS 5,0Эксплойта нетEPSS 3 %ecava · integraxor30 апр. 2014 г.
- CVE-2014-237721Наблюдать
Ecava IntegraXor SCADA Server Information Exposure Through Environmental Variables
СредняяCVSS 5,0Эксплойта нетEPSS 2 %ecava · integraxor15 сент. 2014 г.
- CVE-2016-230221Наблюдать
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %ecava · integraxor21 апр. 2016 г.
- CVE-2016-230321Наблюдать
CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP headers and conduct
СредняяCVSS 5,3Эксплойта нетEPSS 1 %ecava · integraxor21 апр. 2016 г.
- CVE-2017-1673521Наблюдать
A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %ecava · integraxor20 дек. 2017 г.
- CVE-2017-1673321Наблюдать
A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %ecava · integraxor20 дек. 2017 г.
- CVE-2014-075220Наблюдать
Ecava IntegraXor Exposure of Access Control List Files to an Unauthorized Control Sphere
СредняяCVSS 5,0Эксплойта нетEPSS 2 %ecava · integraxor9 янв. 2014 г.
- CVE-2011-295817Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Ecava IntegraXor before 3.60 (Build 4080) allow remote attackers to inject arbitrary
СредняяCVSS 4,3Эксплойта нетEPSS 1 %ecava · integraxor28 июл. 2011 г.
- CVE-2016-230417Наблюдать
Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easi
СредняяCVSS 4,3Эксплойта нетEPSS 1 %ecava · integraxor21 апр. 2016 г.