VendorsIntesyncminiweball versions
Vulnerabilities

Intesync Miniweb

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2009-3419
SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter.
Published 2009-09-25 · Modified
7.51 PoCEPSS 0.009
CVE-2009-4551
SQL injection vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a results action to index.php.
Published 2010-01-04 · Modified
7.51 PoCEPSS 0.009
CVE-2009-3420
Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote attackers to inject arbitrary web script or HTML via the (1) begin parameter and the (2) PATH_INFO.
Published 2009-09-25 · Modified
4.31 PoCEPSS 0.012
CVE-2009-4552
Cross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
Published 2010-01-04 · Modified
4.31 PoCEPSS 0.012