MidnightBSD

Advisories for infor

CVE-2011-1915 HIGH

SQL injection vulnerability in eClient 7.3.2.3 in Enspire Distribution Management Solution 7.3.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
infor enspire_distribution_management_solution 7.3.2.7
infor eclient 7.3.2.3
CVE-2017-7952 MEDIUM

INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
infor enterprise_asset_management 11.0_build_201410
CVE-2017-7953 LOW

INFOR EAM V11.0 Build 201410 has XSS via comment fields.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
infor enterprise_asset_management 11.0