Inventivetec maintains a narrowly scoped portfolio centered on the MediaCast product, a media distribution and streaming platform. The vulnerability profile reflects typical application-layer and data-handling concerns: recurring issues include information disclosure, input validation bypass, cross-site scripting, and SQL injection—patterns common to web-facing content-delivery software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inventivetec over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-2080HIGH Multiple SQL injection vulnerabilities in MediaCAST 8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) a CP_ENLARGESTYLE cookie to the default URI under | May 10, 2011 | 7.5 | 23 | NO | NO |
CVE-2011-2079HIGH MediaCAST 8 and earlier allows remote attackers to have an unspecified impact via a (1) CP_RIGHTSOURCE or (2) bdclient_Inventive cookie to the default URI under inventivex/managetr | May 10, 2011 | 7.5 | 23 | NO | NO |
CVE-2011-2077HIGH The default configuration of the New Atlanta BlueDragon administrative interface in MediaCAST 8 and earlier enables external TCP connections to port 10000, instead of connections o | May 10, 2011 | 7.5 | 23 | NO | NO |
CVE-2010-0216MEDIUM authenticate_ad_setup_finished.cfm in MediaCAST 8 and earlier allows remote attackers to discover usernames and cleartext passwords by reading the error messages returned for reque | May 10, 2011 | 5.0 | 19 | NO | NO |
CVE-2011-2081MEDIUM MediaCAST 8 and earlier does not properly handle requests for inventivex/isptools/release/metadata/globalIncludeFolders.txt, which allows remote attackers to obtain sensitive infor | May 10, 2011 | 5.0 | 18 | NO | NO |
CVE-2011-2076MEDIUM MediaCAST 8 and earlier stores passwords in cleartext, which makes it easier for context-dependent attackers to obtain sensitive information by reading an unspecified password data | May 10, 2011 | 5.0 | 18 | NO | NO |
CVE-2011-2078MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the New Atlanta BlueDragon administrative interface in MediaCAST 8 and earlier allow remote attackers to inject arbitrary web | May 10, 2011 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inventivetec.
Media articles that mention a CVE ID that affects a product developed by Inventivetec — matched by CVE ID, not by vendor name.