Aleris operates a web publishing server product that presents a modestly scoped attack surface centered on application-level data-handling vulnerabilities. The durable signal from its disclosures reflects SQL-injection weaknesses in query construction, a characteristic risk in web publishing platforms that dynamically build database queries from user input. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aleris over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6032HIGH SQL injection vulnerability in calendar/page.asp in Aleris Web Publishing Server 3.0 allows remote attackers to execute arbitrary SQL commands via the mode parameter. | Nov 20, 2007 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aleris.
Media articles that mention a CVE ID that affects a product developed by Aleris — matched by CVE ID, not by vendor name.