Skip to content
Noroxi

phpshe records

14 published records for vendor phpshe.

All records

14 records
  • A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id.

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    phpshe · phpsheMar 13, 2019

  • SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" p

    CriticalCVSS 9.8No exploitEPSS 4%

    phpshe · mall systemApr 28, 2021

  • PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.

    CriticalCVSS 9.8No exploitEPSS 2%

    phpshe · phpsheDec 11, 2020

  • CVE-2019-9626
    39Monitor

    PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpshe · phpsheMar 7, 2019

  • An issue was discovered in PHPSHE 1.7.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpshe · phpsheOct 18, 2018

  • CVE-2018-8943
    39Monitor

    There is a SQL injection in the PHPSHE 1.6 userbank parameter.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpshe · phpsheMar 22, 2018

  • Multiple SQL Injection vulnerabilities in PHPSHE 1.7 in phpshe/admin.php via the (1) ad_id, (2) menu_id, and (3) cashout_id parameters, whic

    HighCVSS 8.8No exploitEPSS 2%

    phpshe · phpsheFeb 9, 2021

  • An issue was discovered in PHPSHE 1.7.

    HighCVSS 7.5No exploitEPSS 2%

    phpshe · phpsheOct 18, 2018

  • CVE-2019-9761
    31Monitor

    An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authenticat

    HighCVSS 7.5No exploitEPSS 2%

    phpshe · phpsheMar 13, 2019

  • phpshe V1.8 is affected by a denial of service (DoS) attack in the registry's verification code, which can paralyze the target service.

    HighCVSS 7.5No exploitEPSS 1%

    phpshe · phpsheMar 30, 2022

  • CVE-2019-6708
    28Monitor

    PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter.

    HighCVSS 7.2No exploitEPSS 1%

    phpshe · phpsheJan 23, 2019

  • CVE-2019-6707
    28Monitor

    PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter.

    HighCVSS 7.2No exploitEPSS 1%

    phpshe · phpsheJan 23, 2019

  • CVE-2025-3553
    21Monitor

    phpshe admin.php pe_delete sql injection

    MediumCVSS 5.3No exploitEPSS 1%

    phpshe · phpsheApr 14, 2025

  • CVE-2025-3554
    21Monitor

    phpshe api.php cross site scripting

    MediumCVSS 5.3No exploitEPSS 1%

    phpshe · phpsheApr 14, 2025