Vulnerabilities
Vulnerable Software
Artica:  >> Integria Ims  Security Vulnerabilities
Integria IMS in its 5.0.92 version does not filter correctly some fields related to the login.php file. An attacker could exploit this vulnerability in order to perform a cross-site scripting attack (XSS).
CVSS Score
5.4
EPSS Score
0.003
Published
2021-10-07
Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit this vulnerability in order to login in the system with different passwords.
CVSS Score
9.8
EPSS Score
0.006
Published
2021-10-07
Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse the AsyncUpload() function in order to exploit the vulnerability.
CVSS Score
9.8
EPSS Score
0.016
Published
2021-10-07
filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload.
CVSS Score
9.8
EPSS Score
0.004
Published
2019-08-16
Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability in Password recovery process, line 45 of general/password_recovery.php that can result in IntegriaIMS web app user accounts can be taken over. This attack appear to be exploitable via Network access to IntegriaIMS web interface . This vulnerability appears to have been fixed in fixed in versions released after commit f2ff0ba821644acecb893483c86a9c4d3bb75047.
CVSS Score
8.1
EPSS Score
0.006
Published
2018-12-20
Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is known.
CVSS Score
6.5
EPSS Score
0.002
Published
2018-12-18
Artica Integria IMS 5.0.83 has XSS via the search_string parameter.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-12-17


Contact Us

Shodan ® - All rights reserved