IblsoftCVEs & Vulnerabilities
3 CVEs affecting Iblsoft products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
3 CVEs→ All vendors
Most Affected Products
online weather 3
CVE-2020-9407MEDIUM
IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie.
26 Feb 2020
5.3
CVSS
CVE-2020-9406CRITICAL
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
26 Feb 2020
9.8
CVSS
CVE-2020-9405MEDIUM
IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page.
26 Feb 2020
6.1
CVSS
← PrevPage 1 / 1Next →