Vulnerabilities (CVE)

Filtered by vendor Iii Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-5127 1 Iii 1 Encore Discovery Solution 2018-10-09 5.8 MEDIUM N/A
Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter.
CVE-2014-5128 1 Iii 1 Encore Discovery Solution 2018-10-09 5.0 MEDIUM N/A
Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitive information via unspecified vectors.
CVE-2014-5136 1 Iii 1 Sierra 2018-10-09 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CVE-2014-5137 1 Iii 1 Sierra 2018-10-09 5.0 MEDIUM N/A
Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of login requests, possibly related to the Webpac Pro submodule.
CVE-2014-2081 1 Iii 1 Vtls-virtua 2015-01-26 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua before 2013.2.4 and 2014.x before 2014.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.