Igreks develops the MilkyStep family of web-based applications with a focused product portfolio that encompasses free, professional, and OEM variants. The recurring weakness classes affecting this vendor—cross-site request forgery, improper access control, cross-site scripting, OS command injection, and SQL injection—reflect the input-handling and authentication challenges common to web applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Igreks over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2956HIGH SQL injection vulnerability in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified v | Jun 13, 2015 | 7.5 | 19 | NO | NO |
CVE-2015-2955HIGH Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. | Jun 13, 2015 | 7.5 | 19 | NO | NO |
CVE-2015-2954MEDIUM Cross-site request forgery (CSRF) vulnerability in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to hijack the authentication of | Jun 13, 2015 | 6.8 | 18 | NO | NO |
CVE-2015-2958MEDIUM Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to bypass intended access restrictions and modify settings via unspecified vectors | Jun 13, 2015 | 6.4 | 17 | NO | NO |
CVE-2015-2952MEDIUM The user-information management functionality in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote authenticated users to bypass intended acce | Jun 13, 2015 | 6.5 | 17 | NO | NO |
CVE-2015-2953MEDIUM Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to bypass intended access restrictions and read files via unspecified vectors, a d | Jun 13, 2015 | 5.0 | 15 | NO | NO |
CVE-2015-2957MEDIUM Cross-site scripting (XSS) vulnerability in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to inject arbitrary web script or HTML | Jun 13, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Igreks.
Media articles that mention a CVE ID that affects a product developed by Igreks — matched by CVE ID, not by vendor name.