Interact maintains a narrowly scoped product line centered on a single platform where the recurring vulnerability signal points to code-injection and code-generation weaknesses. The platform's exposure to these input-handling and dynamic-execution issues reflects its processing of user-controlled data, and public exploit code has frequently emerged for disclosed flaws in this area. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Interact over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2220MEDIUM Multiple PHP remote file inclusion vulnerabilities in Interact Learning Community Environment Interact 2.4.1, when register_globals is enabled, allow remote attackers to execute ar | May 14, 2008 | 6.8 | 29 | NO | YES |
CVE-2007-3328MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Interact 2.4 beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) module_key parameter to (a) kb/ | Jun 21, 2007 | 4.3 | 19 | NO | NO |
CVE-2006-1643HIGH SQL injection vulnerability in login.php in Interact 2.1.1 allows remote attackers to execute arbitrary SQL commands via the user_name parameter. NOTE: the provenance of this info | Apr 6, 2006 | 7.5 | 19 | NO | NO |
CVE-2007-4177MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Interact before 2.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might | Aug 8, 2007 | 4.3 | 15 | NO | NO |
CVE-2006-1644MEDIUM login.php in Interact 2.1.1 generates different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames. NOTE: the pr | Apr 6, 2006 | 5.0 | 15 | NO | NO |
Cross-site scripting (XSS) vulnerability in Interact 2.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) the search_terms parameter to (a) search.php, and | Apr 6, 2006 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Interact.
Media articles that mention a CVE ID that affects a product developed by Interact — matched by CVE ID, not by vendor name.