VYPR

ConnX

by Q2 Solutions

CVEs (3)

  • CVE-2021-40650Jun 14, 2022
    risk 0.00cvss epss 0.00

    In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.

  • CVE-2021-40649Jun 14, 2022
    risk 0.00cvss epss 0.00

    In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.

  • CVE-2009-4947Jul 22, 2010
    risk 0.00cvss epss 0.00

    SQL injection vulnerability in frmLoginPwdReminderPopup.aspx in Q2 Solutions ConnX 4.0.20080606 allows remote attackers to execute arbitrary SQL commands via the txtEmail parameter.