VYPR
Vendor

Intesync

Products
3
CVEs
15
Across products
15
Status
Private

Products

3

Recent CVEs

15
  • CVE-2019-16246CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.03

    Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution.

  • CVE-2019-15936CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.02

    Intesync Solismed 3.3sp allows Insecure File Upload.

  • CVE-2019-15933CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.02

    Intesync Solismed 3.3sp has SQL Injection.

  • CVE-2019-15932CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.02

    Intesync Solismed 3.3sp has Incorrect Access Control.

  • CVE-2019-15931CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.03

    Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246.

  • CVE-2019-15934HigDec 12, 2019
    risk 0.57cvss 8.8epss 0.01

    Intesync Solismed 3.3sp has CSRF.

  • CVE-2019-15935MedDec 12, 2019
    risk 0.40cvss 6.1epss 0.01

    Intesync Solismed 3.3sp has XSS.

  • CVE-2019-17428MedDec 12, 2019
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in Intesync Solismed 3.3sp1. An flaw in the encryption implementation exists, allowing for all encrypted data stored within the database to be decrypted.

  • CVE-2019-15930MedDec 12, 2019
    risk 0.28cvss 4.3epss 0.01

    Intesync Solismed 3.3sp allows Clickjacking.

  • CVE-2009-4552Jan 4, 2010
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

  • CVE-2009-4551Jan 4, 2010
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a results action to index.php.

  • CVE-2009-3420Sep 25, 2009
    risk 0.03cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote attackers to inject arbitrary web script or HTML via the (1) begin parameter and the (2) PATH_INFO.

  • CVE-2009-3419Sep 25, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter.

  • CVE-2008-6582Apr 2, 2009
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.

  • CVE-2008-2197May 14, 2008
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter to index.php.