smartisoft records
9 published records for vendor smartisoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2006-1749Proof of concept | PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code vismartisoft · phplistpro · CWE-94 | High7.5 | — | 8.1% | Apr 12, 2006 |
32Monitor | CVE-2010-2315Proof of concept | PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execute arbitrary PHP codesmartisoft · phpbazar · CWE-94 | High7.5 | — | 5.8% | Jun 17, 2010 |
31Monitor | CVE-2006-2527Proof of concept | Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unauthorized access to tsmartisoft · phpbazar | High7.5 | — | 3.3% | May 22, 2006 |
31Monitor | CVE-2006-2523Proof of concept | PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, allows remote attackesmartisoft · phplistpro | High7.5 | — | 3.0% | May 22, 2006 |
31Monitor | CVE-2009-4222Proof of concept | phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote attackers to obtain acsmartisoft · phpbazar · CWE-264 | High7.5 | — | 2.4% | Dec 7, 2009 |
30Monitor | CVE-2008-3767Proof of concept | SQL injection vulnerability in classified.php in phpBazar 2.0.2 allows remote attackers to execute arbitrary SQL commands via the adid paramsmartisoft · phpbazar · CWE-89 | High7.5 | — | 1.0% | Aug 22, 2008 |
30Monitor | CVE-2009-4221Proof of concept | SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitrary SQL commands viasmartisoft · phpbazar · CWE-89 | High7.5 | — | 1.0% | Dec 7, 2009 |
26Monitor | CVE-2006-2528Proof of concept | PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to execute arbitrary Psmartisoft · phpbazar | Medium6.4 | — | 3.0% | May 22, 2006 |
23Monitor | CVE-2006-2323Proof of concept | Multiple PHP remote file inclusion vulnerabilities in SmartISoft phpListPro 2.01 and earlier allow remote attackers to execute arbitrary PHPsmartisoft · phplistpro | Medium5.1 | — | 9.8% | May 11, 2006 |
- CVE-2006-174932Monitor
PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code vi
HighCVSS 7.5Proof of conceptEPSS 8%smartisoft · phplistproApr 12, 2006
- CVE-2010-231532Monitor
PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execute arbitrary PHP code
HighCVSS 7.5Proof of conceptEPSS 6%smartisoft · phpbazarJun 17, 2010
- CVE-2006-252731Monitor
Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unauthorized access to t
HighCVSS 7.5Proof of conceptEPSS 3%smartisoft · phpbazarMay 22, 2006
- CVE-2006-252331Monitor
PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, allows remote attacke
HighCVSS 7.5Proof of conceptEPSS 3%smartisoft · phplistproMay 22, 2006
- CVE-2009-422231Monitor
phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote attackers to obtain ac
HighCVSS 7.5Proof of conceptEPSS 2%smartisoft · phpbazarDec 7, 2009
- CVE-2008-376730Monitor
SQL injection vulnerability in classified.php in phpBazar 2.0.2 allows remote attackers to execute arbitrary SQL commands via the adid param
HighCVSS 7.5Proof of conceptEPSS 1%smartisoft · phpbazarAug 22, 2008
- CVE-2009-422130Monitor
SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%smartisoft · phpbazarDec 7, 2009
- CVE-2006-252826Monitor
PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to execute arbitrary P
MediumCVSS 6.4Proof of conceptEPSS 3%smartisoft · phpbazarMay 22, 2006
- CVE-2006-232323Monitor
Multiple PHP remote file inclusion vulnerabilities in SmartISoft phpListPro 2.01 and earlier allow remote attackers to execute arbitrary PHP
MediumCVSS 5.1Proof of conceptEPSS 10%smartisoft · phplistproMay 11, 2006