Vulnerabilities
Vulnerable Software
Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists.
CVSS Score
7.5
EPSS Score
0.003
Published
2022-12-09
Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a /admin/temp/surveys/ URI. NOTE: this issue exists because of an incomplete fix for CVE-2018-19550.
CVSS Score
8.8
EPSS Score
0.001
Published
2022-10-11


Contact Us

Shodan ® - All rights reserved