VendorsEcavaintegraxorany version
Vulnerabilities

Ecava Integraxor any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2010-4597
Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Interface (HMI) before 3.5.3900.10 allows remote attackers to execute arbitrary code via a long string in the second argument.
Published 2010-12-23 · Modified
10.01 PoCEPSS 0.188
CVE-2017-6050
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticated attacker to remotely execute arbitrary code in the form of SQL queries.
Published 2017-06-21 · Modified
9.8EPSS 0.035
CVE-2012-0246
Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute arbitrary code via vectors involving an HTML document on the server.
Published 2012-04-02 · Modified
9.3EPSS 0.059
CVE-2012-4700
Multiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attackers to execute arbitrary code via a crafted HTML document.
Published 2013-02-08 · Modified
9.3EPSS 0.038
CVE-2014-2375
Ecava IntegraXor SCADA Server External Control of File Name or Path
Published 2014-09-15 · Modified
9.0EPSS 0.023
CVE-2014-0753
Ecava IntegraXor Stack-based Buffer Overflow
Published 2014-01-21 · Modified
7.8EPSS 0.025
CVE-2016-2306
The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing the network.
Published 2016-04-22 · Modified
7.8EPSS 0.019
CVE-2014-0786
Ecava IntegraXor Information Exposure
Published 2014-05-01 · Modified
7.5EPSS 0.027
CVE-2014-2376
Ecava IntegraXor SCADA Server SQL Injection
Published 2014-09-15 · Modified
7.5EPSS 0.020
CVE-2011-1562
Ecava IntegraXor HMI before n 3.60 (Build 4032) allows remote attackers to bypass authentication and execute arbitrary SQL statements via unspecified vectors related to a crafted POST request. NOTE: some sources have reported this issue as SQL injection, but this might not be accurate.
Published 2011-04-05 · Modified
7.5EPSS 0.017
CVE-2014-0752
Ecava IntegraXor Exposure of Access Control List Files to an Unauthorized Control Sphere
Published 2014-01-09 · Modified
7.5EPSS 0.016
CVE-2016-2299
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Published 2016-04-22 · Modified
7.5EPSS 0.014
CVE-2016-2300
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors.
Published 2016-04-22 · Modified
6.5EPSS 0.012
CVE-2016-2301
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Published 2016-04-22 · Modified
6.5EPSS 0.008
CVE-2016-2305
Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2016-04-22 · Modified
6.1EPSS 0.009
CVE-2016-2302
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.
Published 2016-04-22 · Modified
5.3EPSS 0.012
CVE-2016-2303
CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
Published 2016-04-22 · Modified
5.3EPSS 0.011
CVE-2017-16735
A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which generates an error in the database log.
Published 2017-12-20 · Modified
5.3EPSS 0.010
CVE-2017-16733
A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which an attacker can leverage to disclose sensitive information from the database.
Published 2017-12-20 · Modified
5.3EPSS 0.009
CVE-2010-4598
Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file_name parameter in an open request.
Published 2010-12-23 · Modified
5.01 PoCEPSS 0.265
CVE-2014-2377
Ecava IntegraXor SCADA Server Information Exposure Through Environmental Variables
Published 2014-09-15 · Modified
5.0EPSS 0.018
CVE-2015-0990
Untrusted search path vulnerability in Ecava IntegraXor SCADA Server before 4.2.4488 allows local users to gain privileges via a renamed DLL in the default install directory.
Published 2015-04-03 · Modified
4.4EPSS 0.004
CVE-2011-2958
Multiple cross-site scripting (XSS) vulnerabilities in Ecava IntegraXor before 3.60 (Build 4080) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2011-07-28 · Modified
4.3EPSS 0.012
CVE-2016-2304
Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Published 2016-04-22 · Modified
4.3EPSS 0.011