RSS   Vulnerabilities for 'Email marketer'   RSS

2018-11-28
 
CVE-2018-19651

CWE-918
 

 
admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= request with an http or https URL. This also allows reading local files with a file: URL.

 
2018-11-26
 
CVE-2018-19553

CWE-89
 

 
Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php

 
 
CVE-2018-19552

CWE-89
 

 
Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php.

 
 
CVE-2018-19551

CWE-89
 

 
Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php.

 
 
CVE-2018-19550

CWE-434
 

 
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a admin/temp/surveys/ URI.

 
 
CVE-2018-19549

CWE-89
 

 
Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php.

 
2017-10-18
 
CVE-2017-14322

CWE-287
 

 
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attackers to bypass authentication and obtain administrative access by using the IEM_CookieLogin cookie with a specially crafted value.

 

 >>> Vendor: Interspire 10 Products
Shopping cart
Articlelive
Articlelive nx
Fastfind
Trackpoint nx
Sendstudio
Activekb nx
Activekb
Knowledge manager
Email marketer


Copyright 2024, cxsecurity.com

 

Back to Top