VendorsIgreksmilkystep_professional_oemany version
Vulnerabilities

Igreks MilkyStep Professional OEM any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2015-2955
Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Published 2015-06-13 · Modified
7.5EPSS 0.016
CVE-2015-2956
SQL injection vulnerability in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Published 2015-06-13 · Modified
7.5EPSS 0.013
CVE-2015-2954
Cross-site request forgery (CSRF) vulnerability in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to hijack the authentication of arbitrary users.
Published 2015-06-13 · Modified
6.8EPSS 0.006
CVE-2015-2952
The user-information management functionality in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote authenticated users to bypass intended access restrictions and modify administrative credentials via unspecified vectors, a different vulnerability than CVE-2015-2953 and CVE-2015-2958.
Published 2015-06-13 · Modified
6.5EPSS 0.012
CVE-2015-2958
Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to bypass intended access restrictions and modify settings via unspecified vectors, a different vulnerability than CVE-2015-2952 and CVE-2015-2953.
Published 2015-06-13 · Modified
6.4EPSS 0.015
CVE-2015-2953
Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to bypass intended access restrictions and read files via unspecified vectors, a different vulnerability than CVE-2015-2952 and CVE-2015-2958.
Published 2015-06-13 · Modified
5.0EPSS 0.014
CVE-2015-2957
Cross-site scripting (XSS) vulnerability in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2015-06-13 · Modified
4.3EPSS 0.012