interspire kayıtları
interspire üreticisine ait 25 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-287 Improper Authentication2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-264 Permissions, Privileges, and Access Controls1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
25 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
50Planlayın | CVE-2017-14322Kavram kanıtı | The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remointerspire · email marketer · CWE-287 | Kritik9,8 | — | %36,5 | 18 Eki 2017 |
37İzleyin | CVE-2018-19550Kavram kanıtı | Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, winterspire · email marketer · CWE-434 | Yüksek8,8 | — | %6,0 | 26 Kas 2018 |
35İzleyin | CVE-2018-19552İstismar yok | Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php.interspire · email marketer · CWE-89 | Yüksek8,8 | — | %1,0 | 26 Kas 2018 |
35İzleyin | CVE-2018-19553İstismar yok | Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.phpinterspire · email marketer · CWE-89 | Yüksek8,8 | — | %1,0 | 26 Kas 2018 |
35İzleyin | CVE-2018-19549İstismar yok | Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php.interspire · email marketer · CWE-89 | Yüksek8,8 | — | %1,0 | 26 Kas 2018 |
35İzleyin | CVE-2018-19551İstismar yok | Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php.interspire · email marketer · CWE-89 | Yüksek8,8 | — | %1,0 | 26 Kas 2018 |
35İzleyin | CVE-2022-40777İstismar yok | Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, winterspire · email marketer · CWE-434 | Yüksek8,8 | — | %0,9 | 11 Eki 2022 |
32İzleyin | CVE-2008-2338Kavram kanıtı | Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecifiedinterspire · activekb · CWE-264 | Yüksek7,5 | — | %6,4 | 19 May 2008 |
31İzleyin | CVE-2009-4957Kavram kanıtı | Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary files and possibly have interspire · activekb · CWE-22 | Yüksek7,5 | — | %2,4 | 22 Tem 2010 |
31İzleyin | CVE-2005-1482İstismar yok | ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie.interspire · articlelive | Yüksek7,5 | — | %1,9 | 11 May 2005 |
30İzleyin | CVE-2009-0412İstismar yok | The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass autheinterspire · shopping cart · CWE-287 | Yüksek7,5 | — | %1,5 | 3 Şub 2009 |
30İzleyin | CVE-2005-3726İstismar yok | SQL injection vulnerability in Interspire ArticleLive NX 0.3 allows remote attackers to execute arbitrary SQL commands via the Query parametinterspire · articlelive nx | Yüksek7,5 | — | %1,2 | 21 Kas 2005 |
30İzleyin | CVE-2007-5131Kavram kanıtı | SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the catinterspire · activekb nx · CWE-89 | Yüksek7,5 | — | %1,2 | 27 Eyl 2007 |
30İzleyin | CVE-2007-4147İstismar yok | Multiple unspecified vulnerabilities in Interspire ArticleLive NX before 1.7.1.2 have unknown impact and attack vectors, possibly related tointerspire · articlelive nx | Yüksek7,5 | — | %1,1 | 3 Ağu 2007 |
30İzleyin | CVE-2022-44790İstismar yok | Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module.interspire · email marketer · CWE-89 | Yüksek7,5 | — | %0,6 | 9 Ara 2022 |
29İzleyin | CVE-2007-1060Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl arinterspire · sendstudio | Orta6,8 | — | %8,0 | 21 Şub 2007 |
26İzleyin | CVE-2018-19651İstismar yok | admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= requeinterspire · email marketer · CWE-918 | Orta6,5 | — | %0,8 | 28 Kas 2018 |
25İzleyin | CVE-2007-5425İstismar yok | SQL injection vulnerability in admin/index.php in Interspire ActiveKB 1.5 allows remote attackers to execute arbitrary SQL commands via the interspire · activekb · CWE-94 | Orta6,4 | — | %1,1 | 12 Eki 2007 |
21İzleyin | CVE-2009-4192Kavram kanıtı | Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary filinterspire · knowledge manager · CWE-22 | Orta5,0 | — | %2,7 | 3 Ara 2009 |
18İzleyin | CVE-2005-0881Kavram kanıtı | Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary interspire · articlelive | Orta4,3 | — | %3,5 | 23 Mar 2005 |
18İzleyin | CVE-2006-0210Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary webinterspire · trackpoint nx | Orta4,3 | — | %2,0 | 13 Oca 2006 |
18İzleyin | CVE-2007-5426Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in ActiveKB NX 2.5.4 allow remote attackers to inject arbitrary web script or HTML via tinterspire · activekb nx · CWE-79 | Orta4,3 | — | %1,8 | 12 Eki 2007 |
17İzleyin | CVE-2005-1483İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in ArticleLive 2005 allow remote attackers to inject arbitrary web script or HTML via thinterspire · articlelive | Orta4,3 | — | %1,4 | 11 May 2005 |
17İzleyin | CVE-2008-1076İstismar yok | Cross-site scripting (XSS) vulnerability in search.php in Interspire Shopping Cart 1.x allows remote attackers to inject arbitrary web scripinterspire · shopping cart · CWE-79 | Orta4,3 | — | %1,0 | 28 Şub 2008 |
17İzleyin | CVE-2005-4024İstismar yok | Cross-site scripting (XSS) vulnerability in Interspire FastFind 2004 and 2005 allows remote attackers to inject arbitrary web script or HTMLinterspire · fastfind | Orta4,3 | — | %0,9 | 5 Ara 2005 |
- CVE-2017-1432250Planlayın
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remo
KritikCVSS 9,8Kavram kanıtıEPSS %37interspire · email marketer18 Eki 2017
- CVE-2018-1955037İzleyin
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, w
YüksekCVSS 8,8Kavram kanıtıEPSS %6interspire · email marketer26 Kas 2018
- CVE-2018-1955235İzleyin
Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php.
YüksekCVSS 8,8İstismar yokEPSS %1interspire · email marketer26 Kas 2018
- CVE-2018-1955335İzleyin
Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php
YüksekCVSS 8,8İstismar yokEPSS %1interspire · email marketer26 Kas 2018
- CVE-2018-1954935İzleyin
Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php.
YüksekCVSS 8,8İstismar yokEPSS %1interspire · email marketer26 Kas 2018
- CVE-2018-1955135İzleyin
Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php.
YüksekCVSS 8,8İstismar yokEPSS %1interspire · email marketer26 Kas 2018
- CVE-2022-4077735İzleyin
Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, w
YüksekCVSS 8,8İstismar yokEPSS %1interspire · email marketer11 Eki 2022
- CVE-2008-233832İzleyin
Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified
YüksekCVSS 7,5Kavram kanıtıEPSS %6interspire · activekb19 May 2008
- CVE-2009-495731İzleyin
Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary files and possibly have
YüksekCVSS 7,5Kavram kanıtıEPSS %2interspire · activekb22 Tem 2010
- CVE-2005-148231İzleyin
ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie.
YüksekCVSS 7,5İstismar yokEPSS %2interspire · articlelive11 May 2005
- CVE-2009-041230İzleyin
The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authe
YüksekCVSS 7,5İstismar yokEPSS %2interspire · shopping cart3 Şub 2009
- CVE-2005-372630İzleyin
SQL injection vulnerability in Interspire ArticleLive NX 0.3 allows remote attackers to execute arbitrary SQL commands via the Query paramet
YüksekCVSS 7,5İstismar yokEPSS %1interspire · articlelive nx21 Kas 2005
- CVE-2007-513130İzleyin
SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the cat
YüksekCVSS 7,5Kavram kanıtıEPSS %1interspire · activekb nx27 Eyl 2007
- CVE-2007-414730İzleyin
Multiple unspecified vulnerabilities in Interspire ArticleLive NX before 1.7.1.2 have unknown impact and attack vectors, possibly related to
YüksekCVSS 7,5İstismar yokEPSS %1interspire · articlelive nx3 Ağu 2007
- CVE-2022-4479030İzleyin
Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module.
YüksekCVSS 7,5İstismar yokEPSS %1interspire · email marketer9 Ara 2022
- CVE-2007-106029İzleyin
Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl ar
OrtaCVSS 6,8Kavram kanıtıEPSS %8interspire · sendstudio21 Şub 2007
- CVE-2018-1965126İzleyin
admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= reque
OrtaCVSS 6,5İstismar yokEPSS %1interspire · email marketer28 Kas 2018
- CVE-2007-542525İzleyin
SQL injection vulnerability in admin/index.php in Interspire ActiveKB 1.5 allows remote attackers to execute arbitrary SQL commands via the
OrtaCVSS 6,4İstismar yokEPSS %1interspire · activekb12 Eki 2007
- CVE-2009-419221İzleyin
Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary fil
OrtaCVSS 5,0Kavram kanıtıEPSS %3interspire · knowledge manager3 Ara 2009
- CVE-2005-088118İzleyin
Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary
OrtaCVSS 4,3Kavram kanıtıEPSS %4interspire · articlelive23 Mar 2005
- CVE-2006-021018İzleyin
Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web
OrtaCVSS 4,3Kavram kanıtıEPSS %2interspire · trackpoint nx13 Oca 2006
- CVE-2007-542618İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in ActiveKB NX 2.5.4 allow remote attackers to inject arbitrary web script or HTML via t
OrtaCVSS 4,3Kavram kanıtıEPSS %2interspire · activekb nx12 Eki 2007
- CVE-2005-148317İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in ArticleLive 2005 allow remote attackers to inject arbitrary web script or HTML via th
OrtaCVSS 4,3İstismar yokEPSS %1interspire · articlelive11 May 2005
- CVE-2008-107617İzleyin
Cross-site scripting (XSS) vulnerability in search.php in Interspire Shopping Cart 1.x allows remote attackers to inject arbitrary web scrip
OrtaCVSS 4,3İstismar yokEPSS %1interspire · shopping cart28 Şub 2008
- CVE-2005-402417İzleyin
Cross-site scripting (XSS) vulnerability in Interspire FastFind 2004 and 2005 allows remote attackers to inject arbitrary web script or HTML
OrtaCVSS 4,3İstismar yokEPSS %1interspire · fastfind5 Ara 2005