Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2022-44790 Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack… Email Marketer after 6.5.1 Fix from $1,9502022-12-09 HIGH 8.8 CVE-2022-40777 Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can … Email Marketer after 6.5.0 Fix from $1,9502022-10-11 MEDIUM 6.5 CVE-2018-19651 admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= request with a… Email Marketer after 6.1.6 Fix from $1,6002018-11-28 HIGH 8.8 CVE-2018-19549 Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php. Email Marketer after 6.1.6 Fix from $1,9502018-11-26 HIGH 8.8 CVE-2018-19550EPSS 6% Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can … Email Marketer after 6.1.6 Fix from $1,9502018-11-26 HIGH 8.8 CVE-2018-19551 Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php. Email Marketer after 6.1.6 Fix from $1,9502018-11-26 HIGH 8.8 CVE-2018-19552 Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php. Email Marketer after 6.1.6 Fix from $1,9502018-11-26 HIGH 8.8 CVE-2018-19553 Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php Email Marketer after 6.1.6 Fix from $1,9502018-11-26 CRITICAL 9.8 CVE-2017-14322EPSS 37% The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attack… Email Marketer after 6.1.5 Fix from $2,3002017-10-18 HIGH 7.5 CVE-2009-4957 Directory traversal vulnerability in loadpanel.php in Interspire ActiveKB allows remote attackers to read arbitrary files and possibly have unspecifi… Activekb No fix yet Fix from $1,9502010-07-22 MEDIUM 5.0 CVE-2009-4192 Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a … Knowledge Manager No fix yet Fix from $1,6002009-12-03 HIGH 7.5 CVE-2009-0412 The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication… Shopping Cart Mitigation only Fix from $1,9502009-02-03 HIGH 7.5 CVE-2008-2338EPSS 6% Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts … Activekb after 1.5 Fix from $1,9502008-05-19 MEDIUM 6.4 CVE-2007-5425 SQL injection vulnerability in admin/index.php in Interspire ActiveKB 1.5 allows remote attackers to execute arbitrary SQL commands via the questId p… Activekb No fix yet Fix from $1,6002007-10-12 HIGH 7.5 CVE-2007-5131 SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the catId parame… Activekb Nx No fix yet Fix from $1,9502007-09-27 HIGH 7.5 CVE-2007-4147 Multiple unspecified vulnerabilities in Interspire ArticleLive NX before 1.7.1.2 have unknown impact and attack vectors, possibly related to (1) AL_S… Articlelive Nx Patch available Fix from $1,9502007-08-03 MEDIUM 6.8 CVE-2007-1060EPSS 8% Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled… Sendstudio after 2004.14 Fix from $1,6002007-02-22 HIGH 7.5 CVE-2005-3726 SQL injection vulnerability in Interspire ArticleLive NX 0.3 allows remote attackers to execute arbitrary SQL commands via the Query parameter. Articlelive Nx Patch available Fix from $1,9502005-11-21 HIGH 7.5 CVE-2005-1482 ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie. Articlelive No fix yet Fix from $1,9502005-05-11