Skip to content
Noroxi

cactusoft records

8 published records for vendor cactusoft.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    8 records
    • CVE-2007-3061
      32Monitor

      Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to d

      HighCVSS 7.8Proof of conceptEPSS 3%

      cactusoft · cactushopJun 5, 2007

    • CVE-2004-1881
      31Monitor

      SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL comm

      HighCVSS 7.5Proof of conceptEPSS 3%

      cactusoft · cactushopDec 31, 2004

    • CVE-2006-5991
      30Monitor

      Multiple SQL injection vulnerabilities in wwweb concepts CactuShop allow remote attackers to execute arbitrary SQL commands via the (1) prod

      HighCVSS 7.5No exploitEPSS 1%

      cactusoft · cactushopNov 20, 2006

    • CVE-2006-1005
      25Monitor

      agencyprofile.asp in Parodia 6.2 and earlier might allow remote attackers to obtain sensitive information by triggering an SQL error via an

      MediumCVSS 6.4No exploitEPSS 1%

      cactusoft · parodiaMar 6, 2006

    • CVE-2004-0260
      20Monitor

      The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via

      MediumCVSS 5.0No exploitEPSS 1%

      cactusoft · cactushop liteNov 23, 2004

    • CVE-2004-1882
      18Monitor

      Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or H

      MediumCVSS 4.3Proof of conceptEPSS 4%

      cactusoft · cactushopDec 31, 2004

    • CVE-2006-1004
      17Monitor

      Cross-site scripting (XSS) vulnerability in agencyprofile.asp in Parodia 6.2 and earlier allows remote attackers to inject arbitrary web scr

      MediumCVSS 4.3No exploitEPSS 1%

      cactusoft · parodiaMar 6, 2006

    • CVE-2007-2818
      17Monitor

      Cross-site scripting (XSS) vulnerability in cand_login.asp in CactuSoft Parodia 6.4 and earlier allows remote attackers to inject arbitrary

      MediumCVSS 4.3No exploitEPSS 1%

      cactusoft · parodiaMay 22, 2007