Evalsmsi
Vendor:
First CVE: Feb 11, 2010 · Active for 16 years
4
Total CVEs
More Total CVEs than 72% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Evalsmsi over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 11, 2010
16 years ago
Most Recent CVE
Feb 11, 2010
6,007 days ago
CVE Severity & Scoring
Evalsmsi4 CVEs
50%
50%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown4 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown4 (100.0%)
User Interaction
None0 (0.0%)
Unknown4 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown4 (100.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-0614HIGH SQL injection vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to execute arbitrary SQL commands via the query parameter in the (1) question action, and possibl | Feb 11, 2010 | 7.5 | 28 | NO | YES |
CVE-2010-0616HIGH evalSMSI 2.1.03 stores passwords in cleartext in the database, which allows attackers with database access to gain privileges. NOTE: remote attack vectors are possible by leveragi | Feb 11, 2010 | 7.5 | 19 | NO | NO |
CVE-2010-0617MEDIUM Cross-site scripting (XSS) vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to inject arbitrary web script or HTML via the return parameter. NOTE: the provenan | Feb 11, 2010 | 4.3 | 15 | NO | NO |
CVE-2010-0615MEDIUM Cross-site scripting (XSS) vulnerability in assess.php in evalSMSI 2.1.03 allows remote attackers to inject arbitrary web script or HTML via the reports comment box in a continue_a | Feb 11, 2010 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
25.0% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Evalsmsi
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1.03 | 4 | 5.9 | 1.2% | 0 | 1 |