Записи interspire
25 опубликованных записей вендора interspire.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-287 Improper Authentication2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-264 Permissions, Privileges, and Access Controls1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
25 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
50В плане | CVE-2017-14322Proof of concept | The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remointerspire · email marketer · CWE-287 | Критическая9,8 | — | 36,5 % | 18 окт. 2017 г. |
37Наблюдать | CVE-2018-19550Proof of concept | Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, winterspire · email marketer · CWE-434 | Высокая8,8 | — | 6,0 % | 26 нояб. 2018 г. |
35Наблюдать | CVE-2018-19552Эксплойта нет | Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php.interspire · email marketer · CWE-89 | Высокая8,8 | — | 1,0 % | 26 нояб. 2018 г. |
35Наблюдать | CVE-2018-19553Эксплойта нет | Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.phpinterspire · email marketer · CWE-89 | Высокая8,8 | — | 1,0 % | 26 нояб. 2018 г. |
35Наблюдать | CVE-2018-19549Эксплойта нет | Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php.interspire · email marketer · CWE-89 | Высокая8,8 | — | 1,0 % | 26 нояб. 2018 г. |
35Наблюдать | CVE-2018-19551Эксплойта нет | Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php.interspire · email marketer · CWE-89 | Высокая8,8 | — | 1,0 % | 26 нояб. 2018 г. |
35Наблюдать | CVE-2022-40777Эксплойта нет | Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, winterspire · email marketer · CWE-434 | Высокая8,8 | — | 0,9 % | 11 окт. 2022 г. |
32Наблюдать | CVE-2008-2338Proof of concept | Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecifiedinterspire · activekb · CWE-264 | Высокая7,5 | — | 6,4 % | 19 мая 2008 г. |
31Наблюдать | CVE-2009-4957Proof of concept | Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary files and possibly have interspire · activekb · CWE-22 | Высокая7,5 | — | 2,4 % | 22 июл. 2010 г. |
31Наблюдать | CVE-2005-1482Эксплойта нет | ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie.interspire · articlelive | Высокая7,5 | — | 1,9 % | 11 мая 2005 г. |
30Наблюдать | CVE-2009-0412Эксплойта нет | The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass autheinterspire · shopping cart · CWE-287 | Высокая7,5 | — | 1,5 % | 3 февр. 2009 г. |
30Наблюдать | CVE-2005-3726Эксплойта нет | SQL injection vulnerability in Interspire ArticleLive NX 0.3 allows remote attackers to execute arbitrary SQL commands via the Query parametinterspire · articlelive nx | Высокая7,5 | — | 1,2 % | 21 нояб. 2005 г. |
30Наблюдать | CVE-2007-5131Proof of concept | SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the catinterspire · activekb nx · CWE-89 | Высокая7,5 | — | 1,2 % | 27 сент. 2007 г. |
30Наблюдать | CVE-2007-4147Эксплойта нет | Multiple unspecified vulnerabilities in Interspire ArticleLive NX before 1.7.1.2 have unknown impact and attack vectors, possibly related tointerspire · articlelive nx | Высокая7,5 | — | 1,1 % | 3 авг. 2007 г. |
30Наблюдать | CVE-2022-44790Эксплойта нет | Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module.interspire · email marketer · CWE-89 | Высокая7,5 | — | 0,6 % | 9 дек. 2022 г. |
29Наблюдать | CVE-2007-1060Proof of concept | Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl arinterspire · sendstudio | Средняя6,8 | — | 8,0 % | 21 февр. 2007 г. |
26Наблюдать | CVE-2018-19651Эксплойта нет | admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= requeinterspire · email marketer · CWE-918 | Средняя6,5 | — | 0,8 % | 28 нояб. 2018 г. |
25Наблюдать | CVE-2007-5425Эксплойта нет | SQL injection vulnerability in admin/index.php in Interspire ActiveKB 1.5 allows remote attackers to execute arbitrary SQL commands via the interspire · activekb · CWE-94 | Средняя6,4 | — | 1,1 % | 12 окт. 2007 г. |
21Наблюдать | CVE-2009-4192Proof of concept | Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary filinterspire · knowledge manager · CWE-22 | Средняя5,0 | — | 2,7 % | 3 дек. 2009 г. |
18Наблюдать | CVE-2005-0881Proof of concept | Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary interspire · articlelive | Средняя4,3 | — | 3,5 % | 23 мар. 2005 г. |
18Наблюдать | CVE-2006-0210Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary webinterspire · trackpoint nx | Средняя4,3 | — | 2,0 % | 13 янв. 2006 г. |
18Наблюдать | CVE-2007-5426Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in ActiveKB NX 2.5.4 allow remote attackers to inject arbitrary web script or HTML via tinterspire · activekb nx · CWE-79 | Средняя4,3 | — | 1,8 % | 12 окт. 2007 г. |
17Наблюдать | CVE-2005-1483Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in ArticleLive 2005 allow remote attackers to inject arbitrary web script or HTML via thinterspire · articlelive | Средняя4,3 | — | 1,4 % | 11 мая 2005 г. |
17Наблюдать | CVE-2008-1076Эксплойта нет | Cross-site scripting (XSS) vulnerability in search.php in Interspire Shopping Cart 1.x allows remote attackers to inject arbitrary web scripinterspire · shopping cart · CWE-79 | Средняя4,3 | — | 1,0 % | 28 февр. 2008 г. |
17Наблюдать | CVE-2005-4024Эксплойта нет | Cross-site scripting (XSS) vulnerability in Interspire FastFind 2004 and 2005 allows remote attackers to inject arbitrary web script or HTMLinterspire · fastfind | Средняя4,3 | — | 0,9 % | 5 дек. 2005 г. |
- CVE-2017-1432250В плане
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remo
КритическаяCVSS 9,8Proof of conceptEPSS 37 %interspire · email marketer18 окт. 2017 г.
- CVE-2018-1955037Наблюдать
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, w
ВысокаяCVSS 8,8Proof of conceptEPSS 6 %interspire · email marketer26 нояб. 2018 г.
- CVE-2018-1955235Наблюдать
Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %interspire · email marketer26 нояб. 2018 г.
- CVE-2018-1955335Наблюдать
Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %interspire · email marketer26 нояб. 2018 г.
- CVE-2018-1954935Наблюдать
Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %interspire · email marketer26 нояб. 2018 г.
- CVE-2018-1955135Наблюдать
Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %interspire · email marketer26 нояб. 2018 г.
- CVE-2022-4077735Наблюдать
Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, w
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %interspire · email marketer11 окт. 2022 г.
- CVE-2008-233832Наблюдать
Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %interspire · activekb19 мая 2008 г.
- CVE-2009-495731Наблюдать
Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary files and possibly have
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %interspire · activekb22 июл. 2010 г.
- CVE-2005-148231Наблюдать
ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %interspire · articlelive11 мая 2005 г.
- CVE-2009-041230Наблюдать
The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authe
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %interspire · shopping cart3 февр. 2009 г.
- CVE-2005-372630Наблюдать
SQL injection vulnerability in Interspire ArticleLive NX 0.3 allows remote attackers to execute arbitrary SQL commands via the Query paramet
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %interspire · articlelive nx21 нояб. 2005 г.
- CVE-2007-513130Наблюдать
SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the cat
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %interspire · activekb nx27 сент. 2007 г.
- CVE-2007-414730Наблюдать
Multiple unspecified vulnerabilities in Interspire ArticleLive NX before 1.7.1.2 have unknown impact and attack vectors, possibly related to
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %interspire · articlelive nx3 авг. 2007 г.
- CVE-2022-4479030Наблюдать
Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %interspire · email marketer9 дек. 2022 г.
- CVE-2007-106029Наблюдать
Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl ar
СредняяCVSS 6,8Proof of conceptEPSS 8 %interspire · sendstudio21 февр. 2007 г.
- CVE-2018-1965126Наблюдать
admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= reque
СредняяCVSS 6,5Эксплойта нетEPSS 1 %interspire · email marketer28 нояб. 2018 г.
- CVE-2007-542525Наблюдать
SQL injection vulnerability in admin/index.php in Interspire ActiveKB 1.5 allows remote attackers to execute arbitrary SQL commands via the
СредняяCVSS 6,4Эксплойта нетEPSS 1 %interspire · activekb12 окт. 2007 г.
- CVE-2009-419221Наблюдать
Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary fil
СредняяCVSS 5,0Proof of conceptEPSS 3 %interspire · knowledge manager3 дек. 2009 г.
- CVE-2005-088118Наблюдать
Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary
СредняяCVSS 4,3Proof of conceptEPSS 4 %interspire · articlelive23 мар. 2005 г.
- CVE-2006-021018Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web
СредняяCVSS 4,3Proof of conceptEPSS 2 %interspire · trackpoint nx13 янв. 2006 г.
- CVE-2007-542618Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in ActiveKB NX 2.5.4 allow remote attackers to inject arbitrary web script or HTML via t
СредняяCVSS 4,3Proof of conceptEPSS 2 %interspire · activekb nx12 окт. 2007 г.
- CVE-2005-148317Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in ArticleLive 2005 allow remote attackers to inject arbitrary web script or HTML via th
СредняяCVSS 4,3Эксплойта нетEPSS 1 %interspire · articlelive11 мая 2005 г.
- CVE-2008-107617Наблюдать
Cross-site scripting (XSS) vulnerability in search.php in Interspire Shopping Cart 1.x allows remote attackers to inject arbitrary web scrip
СредняяCVSS 4,3Эксплойта нетEPSS 1 %interspire · shopping cart28 февр. 2008 г.
- CVE-2005-402417Наблюдать
Cross-site scripting (XSS) vulnerability in Interspire FastFind 2004 and 2005 allows remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Эксплойта нетEPSS 1 %interspire · fastfind5 дек. 2005 г.