VendorsVisualwaremyconnection_serverall versions
Vulnerabilities

Visualware MyConnection Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2021-27198
An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename= URI. This application is written in Java and is thus cross-platform. The Windows installation runs as SYSTEM, which means that exploitation gives one Administrator privileges on the target system.
Published 2021-02-26 · Modified
10.0EPSS 0.136
CVE-2023-42034
Visualware MyConnection Server doRTAAccessCTConfig Cross-Site Scripting Authentication Bypass Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.014
CVE-2023-42032
Visualware MyConnection Server doRTAAccessUPass Exposed Dangerous Method Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
7.5EPSS 0.012
CVE-2021-27509
In Visualware MyConnection Server before 11.0b build 5382, each published report is not associated with its own access code.
Published 2021-02-19 · Modified
7.5EPSS 0.010
CVE-2023-42033
Visualware MyConnection Server doPostUploadfiles Directory Traversal Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.2EPSS 0.033
CVE-2023-42035
Visualware MyConnection Server doIForward XML External Entity Processing Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
6.5EPSS 0.012
CVE-2014-5113
Multiple cross-site scripting (XSS) vulnerabilities in test.php in Visualware MyConnection Server 9.7i allow remote attackers to inject arbitrary web script or HTML via the (1) testtype, (2) ver, (3) cm, (4) map, (5) lines, (6) pps, (7) bpp, (8) codec, (9) provtext, (10) provtextextra, (11) provlink, or (12) duration parameter.
Published 2014-07-28 · Modified
4.3EPSS 0.019
CVE-2015-2043
Multiple cross-site scripting (XSS) vulnerabilities in Visualware MyConnection Server 8.2b allow remote attackers to inject arbitrary web script or HTML via the (1) bt, (2) variable, or (3) et parameter to myspeed/db/historyitem.
Published 2015-02-25 · Modified
4.3EPSS 0.010