Vulnerabilities > Interchange Development Group > Interchange > 4.8.7

DATE CVE VULNERABILITY TITLE RISK
2008-05-23 CVE-2008-2423 Denial Of Service vulnerability in Interchange
Unspecified vulnerability in Interchange before 5.6.0 and before 5.5.2 allows remote attackers to cause a denial of service via crafted HTTP requests.
network
low complexity
interchange-development-group
critical
10.0
2004-12-31 CVE-2004-2668 SQL-Injection vulnerability in Interchange
SQL injection vulnerability in Interchange before 4.8.9 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
network
low complexity
interchange-development-group
7.5
2004-05-04 CVE-2004-0374 Remote Information Disclosure vulnerability in Interchange
Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HTTP request ending with the "__SQLUSER__" string.
network
low complexity
interchange-development-group
6.4