Vulnerabilities (CVE)

Filtered by vendor Ecava Subscribe
Filtered by product Integraxor
Total 26 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-2304 1 Ecava 1 Integraxor 2025-04-12 4.3 MEDIUM 4.3 MEDIUM
Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
CVE-2015-0990 1 Ecava 1 Integraxor 2025-04-12 4.4 MEDIUM N/A
Untrusted search path vulnerability in Ecava IntegraXor SCADA Server before 4.2.4488 allows local users to gain privileges via a renamed DLL in the default install directory.
CVE-2016-2300 1 Ecava 1 Integraxor 2025-04-12 6.4 MEDIUM 6.5 MEDIUM
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors.
CVE-2016-2299 1 Ecava 1 Integraxor 2025-04-12 7.5 HIGH 7.3 HIGH
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2016-2302 1 Ecava 1 Integraxor 2025-04-12 5.0 MEDIUM 5.3 MEDIUM
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.
CVE-2016-2301 1 Ecava 1 Integraxor 2025-04-12 6.5 MEDIUM 6.3 MEDIUM
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.