彙總 intesync 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
歷史漏洞主要涉及 SQL 注入與跨站腳本 等問題,部分漏洞可能導致 工作階段劫持,並影響 軟體部署與生產負載 相關場景。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2019-17428 | An issue was discovered in Intesync Solismed 3.3sp1. An flaw in the encryption implementation exists, allowing for all encrypted data stored within the database to be decrypted. | [email protected] | 5.9 | 0.09% | 2019-12-12 | 2024-11-21 |
| CVE-2019-16246 | Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution. | [email protected] | 9.8 | 1.28% | 2019-12-12 | 2024-11-21 |
| CVE-2019-15936 | Intesync Solismed 3.3sp allows Insecure File Upload. | [email protected] | 9.8 | 0.52% | 2019-12-12 | 2024-11-21 |
| CVE-2019-15935 | Intesync Solismed 3.3sp has XSS. | [email protected] | 6.1 | 0.42% | 2019-12-12 | 2024-11-21 |
| CVE-2019-15934 | Intesync Solismed 3.3sp has CSRF. | [email protected] | 8.8 | 0.16% | 2019-12-12 | 2024-11-21 |
| CVE-2019-15933 | Intesync Solismed 3.3sp has SQL Injection. | [email protected] | 9.8 | 0.38% | 2019-12-12 | 2024-11-21 |
| CVE-2019-15932 | Intesync Solismed 3.3sp has Incorrect Access Control. | [email protected] | 9.8 | 0.44% | 2019-12-12 | 2024-11-21 |
| CVE-2019-15931 | Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246. | [email protected] | 9.8 | 0.73% | 2019-12-12 | 2024-11-21 |
| CVE-2019-15930 | Intesync Solismed 3.3sp allows Clickjacking. | [email protected] | 4.3 | 0.36% | 2019-12-12 | 2024-11-21 |
| CVE-2009-4552 | Cross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. | [email protected] | 4.3 | 0.46% | 2010-01-04 | 2026-04-23 |
| CVE-2009-4551 | SQL injection vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a results action to index.php. | [email protected] | 7.5 | 0.29% | 2010-01-04 | 2026-04-23 |
| CVE-2009-3420 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote attackers to inject arbitrary web script or HTML via the (1) begin parameter and the (2) PATH_INFO. | [email protected] | 4.3 | 0.46% | 2009-09-25 | 2026-04-23 |
| CVE-2009-3419 | SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter. | [email protected] | 7.5 | 0.29% | 2009-09-25 | 2026-04-23 |