VYPR
Vendor

Softwarepublico

Sign in to watch
Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-15381Cri0.649.80.00Oct 23, 2017SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).
CVE-2017-15379Cri0.649.80.03Oct 23, 2017An authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password.
CVE-2017-15378Hig0.578.80.00Oct 23, 2017SQL Injection exists in the E-Sic 1.0 password reset parameter (aka the cpfcnpj parameter to the /reset URI).
CVE-2017-15380Med0.406.10.00Oct 23, 2017XSS exists in the E-Sic 1.0 /cadastro/index.php URI (aka the requester's registration area) via the nome parameter.