Email Marketer
Interspire · 9 CVEs
Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could…
Dec 9, 2022
Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit…
Oct 11, 2022
admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what…
Nov 28, 2018
Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php
Nov 26, 2018
Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php.
Nov 26, 2018
Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttag…
Nov 26, 2018
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit…
Nov 26, 2018
Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php.
Nov 26, 2018
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior…
Oct 18, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2022-44790 | Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extrac… | HIGH | 0.62% | Dec 9, 2022 |
| CVE-2022-40777 | Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .p… | HIGH | 0.93% | Oct 11, 2022 |
| CVE-2018-19651 | admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= request with an http or… | MEDIUM | 0.85% | Nov 28, 2018 |
| CVE-2018-19553 | Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php | HIGH | 0.98% | Nov 26, 2018 |
| CVE-2018-19552 | Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php. | HIGH | 0.98% | Nov 26, 2018 |
| CVE-2018-19551 | Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php. | HIGH | 0.98% | Nov 26, 2018 |
| CVE-2018-19550 | Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .p… | HIGH | 5.99% | Nov 26, 2018 |
| CVE-2018-19549 | Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php. | HIGH | 0.98% | Nov 26, 2018 |
| CVE-2017-14322 | The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attackers to byp… | CRITICAL | 36.50% | Oct 18, 2017 |
Showing 1 to 9 of 9 CVEs