Записи cactusoft
8 опубликованных записей вендора cactusoft.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
32Наблюдать | CVE-2007-3061Proof of concept | Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to dcactusoft · cactushop · CWE-255 | Высокая7,8 | — | 2,6 % | 5 июн. 2007 г. |
31Наблюдать | CVE-2004-1881Proof of concept | SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commcactusoft · cactushop | Высокая7,5 | — | 3,1 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2006-5991Эксплойта нет | Multiple SQL injection vulnerabilities in wwweb concepts CactuShop allow remote attackers to execute arbitrary SQL commands via the (1) prodcactusoft · cactushop | Высокая7,5 | — | 1,4 % | 20 нояб. 2006 г. |
25Наблюдать | CVE-2006-1005Эксплойта нет | agencyprofile.asp in Parodia 6.2 and earlier might allow remote attackers to obtain sensitive information by triggering an SQL error via an cactusoft · parodia | Средняя6,4 | — | 1,2 % | 6 мар. 2006 г. |
20Наблюдать | CVE-2004-0260Эксплойта нет | The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files viacactusoft · cactushop lite | Средняя5,0 | — | 1,4 % | 23 нояб. 2004 г. |
18Наблюдать | CVE-2004-1882Proof of concept | Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or Hcactusoft · cactushop | Средняя4,3 | — | 4,0 % | 31 дек. 2004 г. |
17Наблюдать | CVE-2006-1004Эксплойта нет | Cross-site scripting (XSS) vulnerability in agencyprofile.asp in Parodia 6.2 and earlier allows remote attackers to inject arbitrary web scrcactusoft · parodia | Средняя4,3 | — | 1,2 % | 6 мар. 2006 г. |
17Наблюдать | CVE-2007-2818Эксплойта нет | Cross-site scripting (XSS) vulnerability in cand_login.asp in CactuSoft Parodia 6.4 and earlier allows remote attackers to inject arbitrary cactusoft · parodia | Средняя4,3 | — | 1,2 % | 22 мая 2007 г. |
- CVE-2007-306132Наблюдать
Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to d
ВысокаяCVSS 7,8Proof of conceptEPSS 3 %cactusoft · cactushop5 июн. 2007 г.
- CVE-2004-188131Наблюдать
SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL comm
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %cactusoft · cactushop31 дек. 2004 г.
- CVE-2006-599130Наблюдать
Multiple SQL injection vulnerabilities in wwweb concepts CactuShop allow remote attackers to execute arbitrary SQL commands via the (1) prod
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %cactusoft · cactushop20 нояб. 2006 г.
- CVE-2006-100525Наблюдать
agencyprofile.asp in Parodia 6.2 and earlier might allow remote attackers to obtain sensitive information by triggering an SQL error via an
СредняяCVSS 6,4Эксплойта нетEPSS 1 %cactusoft · parodia6 мар. 2006 г.
- CVE-2004-026020Наблюдать
The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via
СредняяCVSS 5,0Эксплойта нетEPSS 1 %cactusoft · cactushop lite23 нояб. 2004 г.
- CVE-2004-188218Наблюдать
Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or H
СредняяCVSS 4,3Proof of conceptEPSS 4 %cactusoft · cactushop31 дек. 2004 г.
- CVE-2006-100417Наблюдать
Cross-site scripting (XSS) vulnerability in agencyprofile.asp in Parodia 6.2 and earlier allows remote attackers to inject arbitrary web scr
СредняяCVSS 4,3Эксплойта нетEPSS 1 %cactusoft · parodia6 мар. 2006 г.
- CVE-2007-281817Наблюдать
Cross-site scripting (XSS) vulnerability in cand_login.asp in CactuSoft Parodia 6.4 and earlier allows remote attackers to inject arbitrary
СредняяCVSS 4,3Эксплойта нетEPSS 1 %cactusoft · parodia22 мая 2007 г.