Loading product vulnerabilities…
Total
3
Critical
1
High
0
Medium
2
CISA KEV
0
IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie.
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page.