Записи iii
6 опубликованных записей вендора iii.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2014-2081Proof of concept | Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua before 2013.2.4 and 201iii · vtls-virtua · CWE-89 | Высокая7,5 | — | 2,1 % | 20 окт. 2014 г. |
30Наблюдать | CVE-2014-5138Эксплойта нет | Innovative Interfaces Sierra Library Services Platform 1.2_3 does not properly handle query strings with multiple instances of the same paraiii · sierra | Высокая7,5 | — | 1,6 % | 14 янв. 2020 г. |
24Наблюдать | CVE-2014-5127Эксплойта нет | Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect users to arbitrary weiii · encore discovery solution | Средняя5,8 | — | 2,1 % | 29 авг. 2014 г. |
21Наблюдать | CVE-2014-5128Эксплойта нет | Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitiviii · encore discovery solution · CWE-200 | Средняя5,0 | — | 2,3 % | 29 авг. 2014 г. |
20Наблюдать | CVE-2014-5137Эксплойта нет | Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user aciii · sierra · CWE-200 | Средняя5,0 | — | 1,2 % | 2 сент. 2014 г. |
17Наблюдать | CVE-2014-5136Эксплойта нет | Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject aiii · sierra · CWE-79 | Средняя4,3 | — | 0,9 % | 2 сент. 2014 г. |
- CVE-2014-208131Наблюдать
Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua before 2013.2.4 and 201
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %iii · vtls-virtua20 окт. 2014 г.
- CVE-2014-513830Наблюдать
Innovative Interfaces Sierra Library Services Platform 1.2_3 does not properly handle query strings with multiple instances of the same para
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %iii · sierra14 янв. 2020 г.
- CVE-2014-512724Наблюдать
Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect users to arbitrary we
СредняяCVSS 5,8Эксплойта нетEPSS 2 %iii · encore discovery solution29 авг. 2014 г.
- CVE-2014-512821Наблюдать
Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitiv
СредняяCVSS 5,0Эксплойта нетEPSS 2 %iii · encore discovery solution29 авг. 2014 г.
- CVE-2014-513720Наблюдать
Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user ac
СредняяCVSS 5,0Эксплойта нетEPSS 1 %iii · sierra2 сент. 2014 г.
- CVE-2014-513617Наблюдать
Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject a
СредняяCVSS 4,3Эксплойта нетEPSS 1 %iii · sierra2 сент. 2014 г.