VendorsInterspireemail_marketer6.1.8
Vulnerabilities

Interspire Email Marketer 6.1.8

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2018-19550
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a admin/temp/surveys/ URI.
Published 2018-11-26 · Modified
8.81 PoCEPSS 0.060
CVE-2018-19551
Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php.
Published 2018-11-26 · Modified
8.8EPSS 0.010
CVE-2018-19552
Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php.
Published 2018-11-26 · Modified
8.8EPSS 0.010
CVE-2018-19553
Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php
Published 2018-11-26 · Modified
8.8EPSS 0.010
CVE-2018-19651
admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= request with an http or https URL. This also allows reading local files with a file: URL.
Published 2018-11-28 · Modified
6.5EPSS 0.008