Skyarc develops a suite of web-based content and file-management applications including autotagging, duplicateentry, mailpack, and multifileuploader products, with a vulnerability footprint centered on application-layer input-handling and request-validation issues. The recurring weakness classes across this product line—cross-site request forgery and cross-site scripting—are characteristic of web applications where client-side trust boundaries are underspecified or improperly enforced. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Skyarc over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3994MEDIUM Cross-site request forgery (CSRF) vulnerability in SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier | Nov 3, 2011 | 6.8 | 22 | NO | NO |
CVE-2011-3993MEDIUM SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Mova | Nov 3, 2011 | 5.5 | 19 | NO | NO |
CVE-2008-6448MEDIUM Cross-site scripting (XSS) vulnerability in install.cgi in SKYARC System MTCMS WYSIWYG Editor allows remote attackers to inject arbitrary web script or HTML via unspecified vectors | Mar 9, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Skyarc.
Media articles that mention a CVE ID that affects a product developed by Skyarc — matched by CVE ID, not by vendor name.