Перейти к содержимому
Noroxi

Записи interspire

25 опубликованных записей вендора interspire.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
4
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

25 записей
  • CVE-2017-14322
    50В плане

    The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remo

    КритическаяCVSS 9,8Proof of conceptEPSS 37 %

    interspire · email marketer18 окт. 2017 г.

  • CVE-2018-19550
    37Наблюдать

    Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, w

    ВысокаяCVSS 8,8Proof of conceptEPSS 6 %

    interspire · email marketer26 нояб. 2018 г.

  • CVE-2018-19552
    35Наблюдать

    Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    interspire · email marketer26 нояб. 2018 г.

  • CVE-2018-19553
    35Наблюдать

    Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    interspire · email marketer26 нояб. 2018 г.

  • CVE-2018-19549
    35Наблюдать

    Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    interspire · email marketer26 нояб. 2018 г.

  • CVE-2018-19551
    35Наблюдать

    Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    interspire · email marketer26 нояб. 2018 г.

  • CVE-2022-40777
    35Наблюдать

    Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, w

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    interspire · email marketer11 окт. 2022 г.

  • CVE-2008-2338
    32Наблюдать

    Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified

    ВысокаяCVSS 7,5Proof of conceptEPSS 6 %

    interspire · activekb19 мая 2008 г.

  • CVE-2009-4957
    31Наблюдать

    Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary files and possibly have

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    interspire · activekb22 июл. 2010 г.

  • CVE-2005-1482
    31Наблюдать

    ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    interspire · articlelive11 мая 2005 г.

  • CVE-2009-0412
    30Наблюдать

    The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authe

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    interspire · shopping cart3 февр. 2009 г.

  • CVE-2005-3726
    30Наблюдать

    SQL injection vulnerability in Interspire ArticleLive NX 0.3 allows remote attackers to execute arbitrary SQL commands via the Query paramet

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    interspire · articlelive nx21 нояб. 2005 г.

  • CVE-2007-5131
    30Наблюдать

    SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the cat

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    interspire · activekb nx27 сент. 2007 г.

  • CVE-2007-4147
    30Наблюдать

    Multiple unspecified vulnerabilities in Interspire ArticleLive NX before 1.7.1.2 have unknown impact and attack vectors, possibly related to

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    interspire · articlelive nx3 авг. 2007 г.

  • CVE-2022-44790
    30Наблюдать

    Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    interspire · email marketer9 дек. 2022 г.

  • CVE-2007-1060
    29Наблюдать

    Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl ar

    СредняяCVSS 6,8Proof of conceptEPSS 8 %

    interspire · sendstudio21 февр. 2007 г.

  • CVE-2018-19651
    26Наблюдать

    admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= reque

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    interspire · email marketer28 нояб. 2018 г.

  • CVE-2007-5425
    25Наблюдать

    SQL injection vulnerability in admin/index.php in Interspire ActiveKB 1.5 allows remote attackers to execute arbitrary SQL commands via the

    СредняяCVSS 6,4Эксплойта нетEPSS 1 %

    interspire · activekb12 окт. 2007 г.

  • CVE-2009-4192
    21Наблюдать

    Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary fil

    СредняяCVSS 5,0Proof of conceptEPSS 3 %

    interspire · knowledge manager3 дек. 2009 г.

  • CVE-2005-0881
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary

    СредняяCVSS 4,3Proof of conceptEPSS 4 %

    interspire · articlelive23 мар. 2005 г.

  • CVE-2006-0210
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web

    СредняяCVSS 4,3Proof of conceptEPSS 2 %

    interspire · trackpoint nx13 янв. 2006 г.

  • CVE-2007-5426
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in ActiveKB NX 2.5.4 allow remote attackers to inject arbitrary web script or HTML via t

    СредняяCVSS 4,3Proof of conceptEPSS 2 %

    interspire · activekb nx12 окт. 2007 г.

  • CVE-2005-1483
    17Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in ArticleLive 2005 allow remote attackers to inject arbitrary web script or HTML via th

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    interspire · articlelive11 мая 2005 г.

  • CVE-2008-1076
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in search.php in Interspire Shopping Cart 1.x allows remote attackers to inject arbitrary web scrip

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    interspire · shopping cart28 февр. 2008 г.

  • CVE-2005-4024
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in Interspire FastFind 2004 and 2005 allows remote attackers to inject arbitrary web script or HTML

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    interspire · fastfind5 дек. 2005 г.