PHP Multivendor Ecommerce Project
PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce: vulnerabilidades y CVE
PHP Multivendor Ecommerce Project PHP Multivendor Ecommerce tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-17960 | Alta (8.8) | 0.51% | — | 28 dic 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php. |
| CVE-2017-17959 | Crítica (9.8) | 1.2% | — | 28 dic 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter. |
| CVE-2017-17958 | Media (6.1) | 0.69% | — | 28 dic 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter. |
| CVE-2017-17957 | Crítica (9.8) | 1.2% | — | 28 dic 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter. |
| CVE-2017-17956 | Media (6.1) | 0.69% | — | 28 dic 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter. |
| CVE-2017-17955 | Media (6.1) | 0.69% | — | 28 dic 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter. |
| CVE-2017-17954 | Media (6.1) | 0.69% | — | 28 dic 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the seller-view.php usid parameter. |
| CVE-2017-17953 | Media (6.1) | 0.69% | — | 28 dic 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter. |
| CVE-2017-17952 | Alta (8.6) | 1.1% | — | 28 dic 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address. |
| CVE-2017-17951 | Crítica (9.8) | 1.2% | — | 28 dic 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter. |
| CVE-2017-17624 | Crítica (9.8) | 3.0% | — | 13 dic 2017 | PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter. |