Ecava / Integraxor
26 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2017-16735 | A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which generates an error… | MEDIUM | 5.3 | Dec 20, 2017 |
| CVE-2017-16733 | A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which an attacker can lev… | MEDIUM | 5.3 | Dec 20, 2017 |
| CVE-2017-6050 | A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow… | CRITICAL | 9.8 | Jun 21, 2017 |
| CVE-2016-8341 | An issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. If the quer… | CRITICAL | 9.8 | Feb 13, 2017 |
| CVE-2016-2306 | The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing the network. | HIGH | 7.5 | Apr 22, 2016 |
| CVE-2016-2305 | Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary web script or HTML via a crafted… | MEDIUM | 6.1 | Apr 22, 2016 |
| CVE-2016-2304 | Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attac… | MEDIUM | 4.3 | Apr 22, 2016 |
| CVE-2016-2303 | CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response split… | MEDIUM | 5.3 | Apr 22, 2016 |
| CVE-2016-2302 | Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages. | MEDIUM | 5.3 | Apr 22, 2016 |
| CVE-2016-2301 | SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbitrary SQL commands via unspecified vecto… | MEDIUM | 6.3 | Apr 22, 2016 |
| CVE-2016-2300 | Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors. | MEDIUM | 6.5 | Apr 22, 2016 |
| CVE-2016-2299 | SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | HIGH | 7.3 | Apr 22, 2016 |
| CVE-2015-0990 | Untrusted search path vulnerability in Ecava IntegraXor SCADA Server before 4.2.4488 allows local users to gain privileges via a renamed DLL in the default ins… | MEDIUM | 4.4 | Apr 3, 2015 |
| CVE-2014-2377 | Ecava IntegraXor SCADA Server Information Exposure Through Environmental Variables | MEDIUM | 5.0 | Sep 15, 2014 |
| CVE-2014-2376 | Ecava IntegraXor SCADA Server SQL Injection | HIGH | 7.5 | Sep 15, 2014 |
| CVE-2014-2375 | Ecava IntegraXor SCADA Server External Control of File Name or Path | HIGH | 9.0 | Sep 15, 2014 |
| CVE-2014-0786 | Ecava IntegraXor Information Exposure | HIGH | 7.5 | May 1, 2014 |
| CVE-2014-0753 | Ecava IntegraXor Stack-based Buffer Overflow | HIGH | 7.8 | Jan 21, 2014 |
| CVE-2014-0752 | Ecava IntegraXor Exposure of Access Control List Files to an Unauthorized Control Sphere | HIGH | 7.5 | Jan 9, 2014 |
| CVE-2012-4700 | Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attackers to execute arbi… | HIGH | 9.3 | Feb 8, 2013 |
| CVE-2012-0246 | Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute arbitrary code via… | HIGH | 9.3 | Apr 2, 2012 |
| CVE-2011-2958 | Multiple cross-site scripting (XSS) vulnerabilities in Ecava IntegraXor before 3.60 (Build 4080) allow remote attackers to inject arbitrary web script or HTML… | MEDIUM | 4.3 | Jul 28, 2011 |
| CVE-2011-1562 | Ecava IntegraXor HMI before n 3.60 (Build 4032) allows remote attackers to bypass authentication and execute arbitrary SQL statements via unspecified vectors r… | HIGH | 7.5 | Apr 5, 2011 |
| CVE-2010-4599 | Untrusted search path vulnerability in Ecava IntegraXor 3.6.4000.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current work… | MEDIUM | 6.9 | Dec 23, 2010 |
| CVE-2010-4598 | Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file_nam… | MEDIUM | 5.0 | Dec 23, 2010 |
Showing 1 to 25 of 26 CVEs