Записи peel
15 опубликованных записей вендора peel.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-16 Configuration1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
38Наблюдать | CVE-2021-37593Proof of concept | PEEL Shopping version 9.4.0 allows remote SQL injection.peel · peel shopping · CWE-89 | Критическая9,1 | — | 5,2 % | 30 июл. 2021 г. |
35Наблюдать | CVE-2018-20848Эксплойта нет | Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in tpeel · peel shopping · CWE-79 | Высокая8,8 | — | 0,8 % | 30 июн. 2019 г. |
31Наблюдать | CVE-2008-1507Proof of concept | PEEL, possibly 3.x and earlier, has (1) a default info@peel.fr account with password admin, and (2) a default contact@peel.fr account with ppeel · peel · CWE-16 | Высокая7,5 | — | 2,3 % | 25 мар. 2008 г. |
31Наблюдать | CVE-2008-6892Proof of concept | SQL injection vulnerability in lire/index.php in Peel 3.1 allows remote attackers to execute arbitrary SQL commands via the rubid parameter.peel · peel · CWE-89 | Высокая7,5 | — | 2,0 % | 3 авг. 2009 г. |
30Наблюдать | CVE-2005-3572Эксплойта нет | SQL injection vulnerability in index.php in Peel 2.6 through 2.7 allows remote attackers to execute arbitrary SQL commands via the rubid parpeel · peel | Высокая7,5 | — | 1,2 % | 16 нояб. 2005 г. |
30Наблюдать | CVE-2008-1496Proof of concept | Multiple SQL injection vulnerabilities in PEEL, possibly 3.x and earlier, allow remote attackers to execute arbitrary SQL commands via the (peel · peel · CWE-89 | Высокая7,5 | — | 1,2 % | 25 мар. 2008 г. |
30Наблюдать | CVE-2012-5227Proof of concept | SQL injection vulnerability in administrer/tva.php in Peel SHOPPING 2.8 and 2.9 allows remote attackers to execute arbitrary SQL commands vipeel · peel shopping · CWE-89 | Высокая7,5 | — | 1,1 % | 1 окт. 2012 г. |
27Наблюдать | CVE-2008-1495Proof of concept | Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote authenticated administrapeel · peel · CWE-20 | Средняя6,5 | — | 2,0 % | 25 мар. 2008 г. |
26Наблюдать | CVE-2021-41672Эксплойта нет | PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php.peel · peel shopping · CWE-89 | Средняя6,5 | — | 1,4 % | 15 июн. 2022 г. |
26Наблюдать | CVE-2019-20178Эксплойта нет | Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user.peel · peel shopping · CWE-352 | Средняя6,5 | — | 0,4 % | 9 янв. 2020 г. |
21Наблюдать | CVE-2008-1506Proof of concept | PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which callspeel · peel · CWE-200 | Средняя5,0 | — | 2,4 % | 25 мар. 2008 г. |
21Наблюдать | CVE-2002-2134Proof of concept | haut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to reference a URL on a remotpeel · peel | Средняя5,0 | — | 2,4 % | 31 дек. 2002 г. |
21Наблюдать | CVE-2021-27190Proof of concept | A Stored Cross Site Scripting(XSS) Vulnerability was discovered in PEEL SHOPPING 9.3.0 and 9.4.0, which are publicly available.peel · peel shopping · CWE-79 | Средняя5,4 | — | 1,6 % | 11 февр. 2021 г. |
19Наблюдать | CVE-2018-1000887Эксплойта нет | Peel shopping peel-shopping_9_1_0 version contains a Cross Site Scripting (XSS) vulnerability that can result in an authenticated user injecpeel · peel shopping · CWE-79 | Средняя4,8 | — | 0,7 % | 28 дек. 2018 г. |
17Наблюдать | CVE-2012-5226Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Peel SHOPPING 2.8 and 2.9 allow remote attackers to inject arbitrary web script or HTpeel · peel shopping · CWE-79 | Средняя4,3 | — | 1,6 % | 1 окт. 2012 г. |
- CVE-2021-3759338Наблюдать
PEEL Shopping version 9.4.0 allows remote SQL injection.
КритическаяCVSS 9,1Proof of conceptEPSS 5 %peel · peel shopping30 июл. 2021 г.
- CVE-2018-2084835Наблюдать
Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in t
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %peel · peel shopping30 июн. 2019 г.
- CVE-2008-150731Наблюдать
PEEL, possibly 3.x and earlier, has (1) a default info@peel.fr account with password admin, and (2) a default contact@peel.fr account with p
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %peel · peel25 мар. 2008 г.
- CVE-2008-689231Наблюдать
SQL injection vulnerability in lire/index.php in Peel 3.1 allows remote attackers to execute arbitrary SQL commands via the rubid parameter.
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %peel · peel3 авг. 2009 г.
- CVE-2005-357230Наблюдать
SQL injection vulnerability in index.php in Peel 2.6 through 2.7 allows remote attackers to execute arbitrary SQL commands via the rubid par
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %peel · peel16 нояб. 2005 г.
- CVE-2008-149630Наблюдать
Multiple SQL injection vulnerabilities in PEEL, possibly 3.x and earlier, allow remote attackers to execute arbitrary SQL commands via the (
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %peel · peel25 мар. 2008 г.
- CVE-2012-522730Наблюдать
SQL injection vulnerability in administrer/tva.php in Peel SHOPPING 2.8 and 2.9 allows remote attackers to execute arbitrary SQL commands vi
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %peel · peel shopping1 окт. 2012 г.
- CVE-2008-149527Наблюдать
Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote authenticated administra
СредняяCVSS 6,5Proof of conceptEPSS 2 %peel · peel25 мар. 2008 г.
- CVE-2021-4167226Наблюдать
PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %peel · peel shopping15 июн. 2022 г.
- CVE-2019-2017826Наблюдать
Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %peel · peel shopping9 янв. 2020 г.
- CVE-2008-150621Наблюдать
PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls
СредняяCVSS 5,0Proof of conceptEPSS 2 %peel · peel25 мар. 2008 г.
- CVE-2002-213421Наблюдать
haut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to reference a URL on a remot
СредняяCVSS 5,0Proof of conceptEPSS 2 %peel · peel31 дек. 2002 г.
- CVE-2021-2719021Наблюдать
A Stored Cross Site Scripting(XSS) Vulnerability was discovered in PEEL SHOPPING 9.3.0 and 9.4.0, which are publicly available.
СредняяCVSS 5,4Proof of conceptEPSS 2 %peel · peel shopping11 февр. 2021 г.
- CVE-2018-100088719Наблюдать
Peel shopping peel-shopping_9_1_0 version contains a Cross Site Scripting (XSS) vulnerability that can result in an authenticated user injec
СредняяCVSS 4,8Эксплойта нетEPSS 1 %peel · peel shopping28 дек. 2018 г.
- CVE-2012-522617Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Peel SHOPPING 2.8 and 2.9 allow remote attackers to inject arbitrary web script or HT
СредняяCVSS 4,3Proof of conceptEPSS 2 %peel · peel shopping1 окт. 2012 г.