cactusoft records
8 published records for vendor cactusoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2007-3061Proof of concept | Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to dcactusoft · cactushop · CWE-255 | High7.8 | — | 2.6% | Jun 5, 2007 |
31Monitor | CVE-2004-1881Proof of concept | SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commcactusoft · cactushop | High7.5 | — | 3.1% | Dec 31, 2004 |
30Monitor | CVE-2006-5991No exploit | Multiple SQL injection vulnerabilities in wwweb concepts CactuShop allow remote attackers to execute arbitrary SQL commands via the (1) prodcactusoft · cactushop | High7.5 | — | 1.4% | Nov 20, 2006 |
25Monitor | CVE-2006-1005No exploit | agencyprofile.asp in Parodia 6.2 and earlier might allow remote attackers to obtain sensitive information by triggering an SQL error via an cactusoft · parodia | Medium6.4 | — | 1.2% | Mar 6, 2006 |
20Monitor | CVE-2004-0260No exploit | The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files viacactusoft · cactushop lite | Medium5.0 | — | 1.4% | Nov 23, 2004 |
18Monitor | CVE-2004-1882Proof of concept | Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or Hcactusoft · cactushop | Medium4.3 | — | 4.0% | Dec 31, 2004 |
17Monitor | CVE-2006-1004No exploit | Cross-site scripting (XSS) vulnerability in agencyprofile.asp in Parodia 6.2 and earlier allows remote attackers to inject arbitrary web scrcactusoft · parodia | Medium4.3 | — | 1.2% | Mar 6, 2006 |
17Monitor | CVE-2007-2818No exploit | Cross-site scripting (XSS) vulnerability in cand_login.asp in CactuSoft Parodia 6.4 and earlier allows remote attackers to inject arbitrary cactusoft · parodia | Medium4.3 | — | 1.2% | May 22, 2007 |
- CVE-2007-306132Monitor
Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to d
HighCVSS 7.8Proof of conceptEPSS 3%cactusoft · cactushopJun 5, 2007
- CVE-2004-188131Monitor
SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL comm
HighCVSS 7.5Proof of conceptEPSS 3%cactusoft · cactushopDec 31, 2004
- CVE-2006-599130Monitor
Multiple SQL injection vulnerabilities in wwweb concepts CactuShop allow remote attackers to execute arbitrary SQL commands via the (1) prod
HighCVSS 7.5No exploitEPSS 1%cactusoft · cactushopNov 20, 2006
- CVE-2006-100525Monitor
agencyprofile.asp in Parodia 6.2 and earlier might allow remote attackers to obtain sensitive information by triggering an SQL error via an
MediumCVSS 6.4No exploitEPSS 1%cactusoft · parodiaMar 6, 2006
- CVE-2004-026020Monitor
The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via
MediumCVSS 5.0No exploitEPSS 1%cactusoft · cactushop liteNov 23, 2004
- CVE-2004-188218Monitor
Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or H
MediumCVSS 4.3Proof of conceptEPSS 4%cactusoft · cactushopDec 31, 2004
- CVE-2006-100417Monitor
Cross-site scripting (XSS) vulnerability in agencyprofile.asp in Parodia 6.2 and earlier allows remote attackers to inject arbitrary web scr
MediumCVSS 4.3No exploitEPSS 1%cactusoft · parodiaMar 6, 2006
- CVE-2007-281817Monitor
Cross-site scripting (XSS) vulnerability in cand_login.asp in CactuSoft Parodia 6.4 and earlier allows remote attackers to inject arbitrary
MediumCVSS 4.3No exploitEPSS 1%cactusoft · parodiaMay 22, 2007