Vulnerabilities > Arialsoftware

DATE CVE VULNERABILITY TITLE RISK
2020-01-10 CVE-2012-3821 Incorrect Authorization vulnerability in Arialsoftware Campaign Enterprise
A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malicious user modify the SerialNumber field.
network
low complexity
arialsoftware CWE-863
4.3
2020-01-10 CVE-2012-3824 Improper Authentication vulnerability in Arialsoftware Campaign Enterprise
In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.
network
low complexity
arialsoftware CWE-287
7.5
2020-01-10 CVE-2012-3823 Insufficiently Protected Credentials vulnerability in Arialsoftware Campaign Enterprise
Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
network
low complexity
arialsoftware CWE-522
7.5
2020-01-10 CVE-2012-3822 Incorrect Authorization vulnerability in Arialsoftware Campaign Enterprise
Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' credentials.
network
low complexity
arialsoftware CWE-863
7.5