arialsoftware kayıtları
arialsoftware üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-863 Incorrect Authorization2
- CWE-287 Improper Authentication1
- CWE-522 Insufficiently Protected Credentials1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2012-3820İstismar yok | Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to exearialsoftware · campaign enterprise · CWE-89 | Yüksek7,5 | — | %2,1 | 14 Ağu 2014 |
31İzleyin | CVE-2012-3822İstismar yok | Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate userarialsoftware · campaign enterprise · CWE-863 | Yüksek7,5 | — | %1,9 | 10 Oca 2020 |
31İzleyin | CVE-2012-3824İstismar yok | In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.arialsoftware · campaign enterprise · CWE-287 | Yüksek7,5 | — | %1,8 | 10 Oca 2020 |
30İzleyin | CVE-2012-3823İstismar yok | Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.arialsoftware · campaign enterprise · CWE-522 | Yüksek7,5 | — | %1,5 | 10 Oca 2020 |
17İzleyin | CVE-2012-3821İstismar yok | A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malarialsoftware · campaign enterprise · CWE-863 | Orta4,3 | — | %1,2 | 10 Oca 2020 |
- CVE-2012-382031İzleyin
Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to exe
YüksekCVSS 7,5İstismar yokEPSS %2arialsoftware · campaign enterprise14 Ağu 2014
- CVE-2012-382231İzleyin
Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate user
YüksekCVSS 7,5İstismar yokEPSS %2arialsoftware · campaign enterprise10 Oca 2020
- CVE-2012-382431İzleyin
In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.
YüksekCVSS 7,5İstismar yokEPSS %2arialsoftware · campaign enterprise10 Oca 2020
- CVE-2012-382330İzleyin
Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
YüksekCVSS 7,5İstismar yokEPSS %1arialsoftware · campaign enterprise10 Oca 2020
- CVE-2012-382117İzleyin
A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote mal
OrtaCVSS 4,3İstismar yokEPSS %1arialsoftware · campaign enterprise10 Oca 2020