Записи qualiteam
15 опубликованных записей вендора qualiteam.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2004-0241Proof of concept | X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.qualiteam · x-cart | Критическая10,0 | — | 6,0 % | 23 нояб. 2004 г. |
39Наблюдать | CVE-2006-2827Эксплойта нет | SQL injection vulnerability in search.php in X-Cart Gold and Pro 4.0.18, and X-Cart 4.1.0 beta 1, allows remote attackers to execute arbitraqualiteam · x-cart | Критическая9,8 | — | 1,3 % | 5 июн. 2006 г. |
36Наблюдать | CVE-2017-15285Эксплойта нет | X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution.qualiteam · x-cart · CWE-20 | Высокая8,8 | — | 2,1 % | 12 окт. 2017 г. |
32Наблюдать | CVE-2007-4907Proof of concept | Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dirqualiteam · x-cart · CWE-94 | Высокая7,5 | — | 8,2 % | 17 сент. 2007 г. |
32Наблюдать | CVE-2006-4904Proof of concept | Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to overwrite arbitrary pqualiteam · x-cart | Высокая7,5 | — | 7,0 % | 20 сент. 2006 г. |
31Наблюдать | CVE-2005-1822Proof of concept | Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat orqualiteam · x-cart | Высокая7,5 | — | 2,4 % | 1 июн. 2005 г. |
26Наблюдать | CVE-2015-0951Эксплойта нет | X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2)qualiteam · x-cart · CWE-264 | Средняя6,5 | — | 1,3 % | 4 апр. 2015 г. |
24Наблюдать | CVE-2019-7220Эксплойта нет | X-Cart V5 is vulnerable to XSS via the CategoryFilter2 parameter.qualiteam · x-cart · CWE-79 | Средняя6,1 | — | 0,8 % | 6 июн. 2019 г. |
22Наблюдать | CVE-2004-0242Proof of concept | X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.qualiteam · x-cart | Средняя5,0 | — | 6,9 % | 23 нояб. 2004 г. |
20Наблюдать | CVE-2004-0240Эксплойта нет | Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a ..qualiteam · x-cart | Средняя5,0 | — | 1,5 % | 23 нояб. 2004 г. |
18Наблюдать | CVE-2005-1823Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML qualiteam · x-cart | Средняя4,3 | — | 3,6 % | 1 июн. 2005 г. |
18Наблюдать | CVE-2015-1178Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in cart.php in X-Cart 5.1.8 and earlier allow remote attackers to inject arbitrary web squaliteam · x-cart · CWE-79 | Средняя4,3 | — | 1,9 % | 26 янв. 2015 г. |
17Наблюдать | CVE-2012-2570Proof of concept | Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart Gold 4.5 allows remote attackers to inject arbitrary web script or HTqualiteam · x-cart · CWE-79 | Средняя4,3 | — | 1,7 % | 15 авг. 2012 г. |
17Наблюдать | CVE-2015-5455Эксплойта нет | Cross-site scripting (XSS) vulnerability in X-Cart 4.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspqualiteam · x-cart · CWE-79 | Средняя4,3 | — | 1,5 % | 8 июл. 2015 г. |
17Наблюдать | CVE-2015-0950Эксплойта нет | Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6 through 5.1.10 allows remote attackers to inject arbitrary web script qualiteam · x-cart · CWE-79 | Средняя4,3 | — | 1,2 % | 4 апр. 2015 г. |
- CVE-2004-024142В плане
X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.
КритическаяCVSS 10,0Proof of conceptEPSS 6 %qualiteam · x-cart23 нояб. 2004 г.
- CVE-2006-282739Наблюдать
SQL injection vulnerability in search.php in X-Cart Gold and Pro 4.0.18, and X-Cart 4.1.0 beta 1, allows remote attackers to execute arbitra
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualiteam · x-cart5 июн. 2006 г.
- CVE-2017-1528536Наблюдать
X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %qualiteam · x-cart12 окт. 2017 г.
- CVE-2007-490732Наблюдать
Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dir
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %qualiteam · x-cart17 сент. 2007 г.
- CVE-2006-490432Наблюдать
Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to overwrite arbitrary p
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %qualiteam · x-cart20 сент. 2006 г.
- CVE-2005-182231Наблюдать
Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %qualiteam · x-cart1 июн. 2005 г.
- CVE-2015-095126Наблюдать
X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2)
СредняяCVSS 6,5Эксплойта нетEPSS 1 %qualiteam · x-cart4 апр. 2015 г.
- CVE-2019-722024Наблюдать
X-Cart V5 is vulnerable to XSS via the CategoryFilter2 parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %qualiteam · x-cart6 июн. 2019 г.
- CVE-2004-024222Наблюдать
X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.
СредняяCVSS 5,0Proof of conceptEPSS 7 %qualiteam · x-cart23 нояб. 2004 г.
- CVE-2004-024020Наблюдать
Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a ..
СредняяCVSS 5,0Эксплойта нетEPSS 1 %qualiteam · x-cart23 нояб. 2004 г.
- CVE-2005-182318Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Proof of conceptEPSS 4 %qualiteam · x-cart1 июн. 2005 г.
- CVE-2015-117818Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in cart.php in X-Cart 5.1.8 and earlier allow remote attackers to inject arbitrary web s
СредняяCVSS 4,3Эксплойта нетEPSS 2 %qualiteam · x-cart26 янв. 2015 г.
- CVE-2012-257017Наблюдать
Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart Gold 4.5 allows remote attackers to inject arbitrary web script or HT
СредняяCVSS 4,3Proof of conceptEPSS 2 %qualiteam · x-cart15 авг. 2012 г.
- CVE-2015-545517Наблюдать
Cross-site scripting (XSS) vulnerability in X-Cart 4.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unsp
СредняяCVSS 4,3Эксплойта нетEPSS 1 %qualiteam · x-cart8 июл. 2015 г.
- CVE-2015-095017Наблюдать
Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6 through 5.1.10 allows remote attackers to inject arbitrary web script
СредняяCVSS 4,3Эксплойта нетEPSS 1 %qualiteam · x-cart4 апр. 2015 г.