Vulnerabilities > ICZ

DATE CVE VULNERABILITY TITLE RISK
2015-10-06 CVE-2015-5645 Permissions, Privileges, and Access Controls vulnerability in ICZ Matchasns
ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors.
network
low complexity
icz CWE-264
6.5
2015-10-06 CVE-2015-5644 Code Injection vulnerability in ICZ Matchasns
The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code via unspecified vectors.
network
icz CWE-94
6.8
2015-10-06 CVE-2015-5643 Code Injection vulnerability in ICZ Matchasns
The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code via unspecified vectors.
network
icz CWE-94
6.8
2015-10-06 CVE-2015-5642 SQL Injection vulnerability in ICZ Matchasns
Multiple SQL injection vulnerabilities in ICZ MATCHA INVOICE before 2.5.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
icz CWE-89
6.5
2012-04-06 CVE-2012-1238 Cross-Site Request Forgery vulnerability in ICZ Sencha SNS 1.0.0/1.0.1
Session fixation vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack web sessions via unspecified vectors.
network
icz
4.3
2012-04-06 CVE-2012-1237 Cross-Site Request Forgery (CSRF) vulnerability in ICZ Sencha SNS 1.0.0/1.0.1
Cross-site request forgery (CSRF) vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack the authentication of arbitrary users.
network
icz CWE-352
6.8