Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Email Marketer HIGH 7.5
CVE-2022-44790

Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack…

Fix: after 6.5.1
Fix from $1,950 2022-12-09
Email Marketer HIGH 8.8
CVE-2022-40777

Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can …

Fix: after 6.5.0
Fix from $1,950 2022-10-11
Email Marketer MEDIUM 6.5
CVE-2018-19651

admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= request with a…

Fix: after 6.1.6
Fix from $1,600 2018-11-28
Email Marketer HIGH 8.8
CVE-2018-19549

Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php.

Fix: after 6.1.6
Fix from $1,950 2018-11-26
Email Marketer HIGH 8.8
CVE-2018-19550EPSS 6%

Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can …

Fix: after 6.1.6
Fix from $1,950 2018-11-26
Email Marketer HIGH 8.8
CVE-2018-19551

Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php.

Fix: after 6.1.6
Fix from $1,950 2018-11-26
Email Marketer HIGH 8.8
CVE-2018-19552

Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php.

Fix: after 6.1.6
Fix from $1,950 2018-11-26
Email Marketer HIGH 8.8
CVE-2018-19553

Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php

Fix: after 6.1.6
Fix from $1,950 2018-11-26
Email Marketer CRITICAL 9.8
CVE-2017-14322EPSS 37%

The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attack…

Fix: after 6.1.5
Fix from $2,300 2017-10-18
Activekb HIGH 7.5
CVE-2009-4957

Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary files and possibly have unspecifi…

No fix yet
Fix from $1,950 2010-07-22
Knowledge Manager MEDIUM 5.0
CVE-2009-4192

Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a …

No fix yet
Fix from $1,600 2009-12-03
Shopping Cart HIGH 7.5
CVE-2009-0412

The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication…

Mitigation only
Fix from $1,950 2009-02-03
Activekb HIGH 7.5
CVE-2008-2338EPSS 6%

Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts …

Fix: after 1.5
Fix from $1,950 2008-05-19
Activekb MEDIUM 6.4
CVE-2007-5425

SQL injection vulnerability in admin/index.php in Interspire ActiveKB 1.5 allows remote attackers to execute arbitrary SQL commands via the questId p…

No fix yet
Fix from $1,600 2007-10-12
Activekb Nx HIGH 7.5
CVE-2007-5131

SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the catId parame…

No fix yet
Fix from $1,950 2007-09-27
Articlelive Nx HIGH 7.5
CVE-2007-4147

Multiple unspecified vulnerabilities in Interspire ArticleLive NX before 1.7.1.2 have unknown impact and attack vectors, possibly related to (1) AL_S…

Patch available
Fix from $1,950 2007-08-03
Sendstudio MEDIUM 6.8
CVE-2007-1060EPSS 8%

Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled…

Fix: after 2004.14
Fix from $1,600 2007-02-22
Articlelive Nx HIGH 7.5
CVE-2005-3726

SQL injection vulnerability in Interspire ArticleLive NX 0.3 allows remote attackers to execute arbitrary SQL commands via the Query parameter.

Patch available
Fix from $1,950 2005-11-21
Articlelive HIGH 7.5
CVE-2005-1482

ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie.

No fix yet
Fix from $1,950 2005-05-11