Перейти к содержимому
Noroxi

Записи qualiteam

15 опубликованных записей вендора qualiteam.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
5
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 17
  2. 19

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

15 записей
  • CVE-2004-0241
    42В плане

    X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.

    КритическаяCVSS 10,0Proof of conceptEPSS 6 %

    qualiteam · x-cart23 нояб. 2004 г.

  • CVE-2006-2827
    39Наблюдать

    SQL injection vulnerability in search.php in X-Cart Gold and Pro 4.0.18, and X-Cart 4.1.0 beta 1, allows remote attackers to execute arbitra

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    qualiteam · x-cart5 июн. 2006 г.

  • CVE-2017-15285
    36Наблюдать

    X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    qualiteam · x-cart12 окт. 2017 г.

  • CVE-2007-4907
    32Наблюдать

    Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dir

    ВысокаяCVSS 7,5Proof of conceptEPSS 8 %

    qualiteam · x-cart17 сент. 2007 г.

  • CVE-2006-4904
    32Наблюдать

    Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to overwrite arbitrary p

    ВысокаяCVSS 7,5Proof of conceptEPSS 7 %

    qualiteam · x-cart20 сент. 2006 г.

  • CVE-2005-1822
    31Наблюдать

    Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    qualiteam · x-cart1 июн. 2005 г.

  • CVE-2015-0951
    26Наблюдать

    X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2)

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    qualiteam · x-cart4 апр. 2015 г.

  • CVE-2019-7220
    24Наблюдать

    X-Cart V5 is vulnerable to XSS via the CategoryFilter2 parameter.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    qualiteam · x-cart6 июн. 2019 г.

  • CVE-2004-0242
    22Наблюдать

    X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.

    СредняяCVSS 5,0Proof of conceptEPSS 7 %

    qualiteam · x-cart23 нояб. 2004 г.

  • CVE-2004-0240
    20Наблюдать

    Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a ..

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    qualiteam · x-cart23 нояб. 2004 г.

  • CVE-2005-1823
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML

    СредняяCVSS 4,3Proof of conceptEPSS 4 %

    qualiteam · x-cart1 июн. 2005 г.

  • CVE-2015-1178
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in cart.php in X-Cart 5.1.8 and earlier allow remote attackers to inject arbitrary web s

    СредняяCVSS 4,3Эксплойта нетEPSS 2 %

    qualiteam · x-cart26 янв. 2015 г.

  • CVE-2012-2570
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart Gold 4.5 allows remote attackers to inject arbitrary web script or HT

    СредняяCVSS 4,3Proof of conceptEPSS 2 %

    qualiteam · x-cart15 авг. 2012 г.

  • CVE-2015-5455
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in X-Cart 4.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unsp

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    qualiteam · x-cart8 июл. 2015 г.

  • CVE-2015-0950
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6 through 5.1.10 allows remote attackers to inject arbitrary web script

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    qualiteam · x-cart4 апр. 2015 г.