Vulnerabilities > Interspire > Email Marketer > 5.0.10

DATE CVE VULNERABILITY TITLE RISK
2022-12-09 CVE-2022-44790 SQL Injection vulnerability in Interspire Email Marketer
Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module.
network
low complexity
interspire CWE-89
7.5
2022-10-11 CVE-2022-40777 Unrestricted Upload of File with Dangerous Type vulnerability in Interspire Email Marketer
Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a /admin/temp/surveys/ URI.
network
low complexity
interspire CWE-434
8.8
2018-11-28 CVE-2018-19651 Server-Side Request Forgery (SSRF) vulnerability in Interspire Email Marketer
admin/functions/remote.php in Interspire Email Marketer through 6.1.6 has Server Side Request Forgery (SSRF) via a what=importurl&url= request with an http or https URL.
network
low complexity
interspire CWE-918
6.5
2018-11-26 CVE-2018-19553 SQL Injection vulnerability in Interspire Email Marketer
Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php
network
low complexity
interspire CWE-89
8.8
2018-11-26 CVE-2018-19552 SQL Injection vulnerability in Interspire Email Marketer
Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php.
network
low complexity
interspire CWE-89
8.8
2018-11-26 CVE-2018-19551 SQL Injection vulnerability in Interspire Email Marketer
Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php.
network
low complexity
interspire CWE-89
8.8
2018-11-26 CVE-2018-19550 Unrestricted Upload of File with Dangerous Type vulnerability in Interspire Email Marketer
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a admin/temp/surveys/ URI.
network
low complexity
interspire CWE-434
8.8
2018-11-26 CVE-2018-19549 SQL Injection vulnerability in Interspire Email Marketer
Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php.
network
low complexity
interspire CWE-89
8.8
2017-10-18 CVE-2017-14322 Improper Authentication vulnerability in Interspire Email Marketer
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attackers to bypass authentication and obtain administrative access by using the IEM_CookieLogin cookie with a specially crafted value.
network
low complexity
interspire CWE-287
critical
10.0