Перейти к содержимому
Noroxi

Записи cactusoft

8 опубликованных записей вендора cactusoft.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Повторяющиеся классы

    Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

    CWE

    Все записи

    8 записей
    • CVE-2007-3061
      32Наблюдать

      Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to d

      ВысокаяCVSS 7,8Proof of conceptEPSS 3 %

      cactusoft · cactushop5 июн. 2007 г.

    • CVE-2004-1881
      31Наблюдать

      SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL comm

      ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

      cactusoft · cactushop31 дек. 2004 г.

    • CVE-2006-5991
      30Наблюдать

      Multiple SQL injection vulnerabilities in wwweb concepts CactuShop allow remote attackers to execute arbitrary SQL commands via the (1) prod

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      cactusoft · cactushop20 нояб. 2006 г.

    • CVE-2006-1005
      25Наблюдать

      agencyprofile.asp in Parodia 6.2 and earlier might allow remote attackers to obtain sensitive information by triggering an SQL error via an

      СредняяCVSS 6,4Эксплойта нетEPSS 1 %

      cactusoft · parodia6 мар. 2006 г.

    • CVE-2004-0260
      20Наблюдать

      The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via

      СредняяCVSS 5,0Эксплойта нетEPSS 1 %

      cactusoft · cactushop lite23 нояб. 2004 г.

    • CVE-2004-1882
      18Наблюдать

      Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or H

      СредняяCVSS 4,3Proof of conceptEPSS 4 %

      cactusoft · cactushop31 дек. 2004 г.

    • CVE-2006-1004
      17Наблюдать

      Cross-site scripting (XSS) vulnerability in agencyprofile.asp in Parodia 6.2 and earlier allows remote attackers to inject arbitrary web scr

      СредняяCVSS 4,3Эксплойта нетEPSS 1 %

      cactusoft · parodia6 мар. 2006 г.

    • CVE-2007-2818
      17Наблюдать

      Cross-site scripting (XSS) vulnerability in cand_login.asp in CactuSoft Parodia 6.4 and earlier allows remote attackers to inject arbitrary

      СредняяCVSS 4,3Эксплойта нетEPSS 1 %

      cactusoft · parodia22 мая 2007 г.