Products: 2
    Vulnerabilities: 5
    Known Exploited: 0
    3
    Critical Level Threats
    1
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-34683

    An issue was discovered in EXCELLENT INFOTEK CORPORATION (EIC) E-document System 3.0. A remote attacker can use kw/auth/bbs/asp/get_user_email_info_bbs.asp to obtain the contact information (name and e-mail address) of everyone in the entire organization. This information can allow remote attackers to perform social engineering or brute force attacks against the system login page.

    Last Modified: Nov 21, 2024
    Published: Jun 16, 2021

    CVE-2021-22860

    EIC e-document system - Broken Authentication

    Last Modified: Nov 21, 2024
    Published: Mar 17, 2021

    CVE-2021-22859

    EIC e-document system - SQL Injection

    Last Modified: Nov 21, 2024
    Published: Mar 17, 2021

    CVE-2019-11233

    EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information without being authenticated, by sending a LOGIN_ID element to the auth/main/asp/check_user_login_info.aspx URI, and then reading the response, as demonstrated by the KW_EMAIL or KW_TEL field.

    Last Modified: Nov 21, 2024
    Published: Jun 19, 2019

    CVE-2019-11232

    EXCELLENT INFOTEK BiYan v1.57 ~ v2.8 allows an attacker to leak user information (Password) without being authenticated, by sending an EMP_NO element to the kws_login/asp/query_user.asp URI, and then reading the PWD element.

    Last Modified: Nov 21, 2024
    Published: Jun 19, 2019
    Items Per Page