Website Seller Script Project
Website Seller Script Project Website Seller Script: vulnerabilidades y CVE
Website Seller Script Project Website Seller Script tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-20631 | Media (5.3) | 1.6% | — | 21 mar 2019 | PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such as a .png file. |
| CVE-2018-20530 | Media (5.4) | 0.53% | — | 28 dic 2018 | PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a Profile field such as Company Address, a related issue to CVE-2018-15896. |
| CVE-2018-15897 | Media (6.5) | 1.1% | — | 28 ago 2018 | PHP Scripts Mall Website Seller Script 2.0.5 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, Company Name, or Fax field, as demonstrated by crossPwn. |
| CVE-2018-15896 | Media (5.4) | 0.55% | — | 28 ago 2018 | PHP Scripts Mall Website Seller Script 2.0.5 has XSS via Personal Address or Company Name. |
| CVE-2018-11501 | Alta (8.8) | 0.63% | — | 26 may 2018 | PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS. |
| CVE-2018-6879 | Alta (8.8) | 1.0% | — | 12 abr 2018 | PHP Scripts Mall Website Seller Script 2.0.3 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by removing the validation code. |
| CVE-2018-6870 | Media (6.1) | 0.65% | — | 12 abr 2018 | Reflected XSS exists in PHP Scripts Mall Website Seller Script 2.0.3 via the Listings Search feature. |