Записи ordermanagementscript
8 опубликованных записей вендора ordermanagementscript.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2017-17928Эксплойта нет | PHP Scripts Mall Professional Service Script has SQL injection via the admin/review.php id parameter.ordermanagementscript · professional service script · CWE-89 | Критическая9,8 | — | 1,2 % | 27 дек. 2017 г. |
35Наблюдать | CVE-2017-17930Эксплойта нет | PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user pordermanagementscript · professional service script · CWE-352 | Высокая8,8 | — | 0,5 % | 27 дек. 2017 г. |
35Наблюдать | CVE-2018-6934Эксплойта нет | CSRF exists in student/personal-info in PHP Scripts Mall Online Tutoring Script 2.0.3.ordermanagementscript · online tutoring script · CWE-352 | Высокая8,8 | — | 0,5 % | 12 апр. 2018 г. |
21Наблюдать | CVE-2017-17927Эксплойта нет | PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via a crafted PATH_INFO to seordermanagementscript · professional service script · CWE-22 | Средняя5,3 | — | 1,5 % | 27 дек. 2017 г. |
21Наблюдать | CVE-2017-17924Эксплойта нет | PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via the id parameter to adminordermanagementscript · professional service script · CWE-22 | Средняя5,3 | — | 1,5 % | 27 дек. 2017 г. |
21Наблюдать | CVE-2017-17926Эксплойта нет | PHP Scripts Mall Professional Service Script has a predicable registration URL, which makes it easier for remote attackers to register with ordermanagementscript · professional service script · CWE-200 | Средняя5,3 | — | 1,1 % | 27 дек. 2017 г. |
19Наблюдать | CVE-2017-17929Эксплойта нет | PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter.ordermanagementscript · professional service script · CWE-79 | Средняя4,8 | — | 0,5 % | 27 дек. 2017 г. |
19Наблюдать | CVE-2017-17925Эксплойта нет | PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter.ordermanagementscript · professional service script · CWE-79 | Средняя4,8 | — | 0,5 % | 27 дек. 2017 г. |
- CVE-2017-1792839Наблюдать
PHP Scripts Mall Professional Service Script has SQL injection via the admin/review.php id parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ordermanagementscript · professional service script27 дек. 2017 г.
- CVE-2017-1793035Наблюдать
PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user p
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ordermanagementscript · professional service script27 дек. 2017 г.
- CVE-2018-693435Наблюдать
CSRF exists in student/personal-info in PHP Scripts Mall Online Tutoring Script 2.0.3.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %ordermanagementscript · online tutoring script12 апр. 2018 г.
- CVE-2017-1792721Наблюдать
PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via a crafted PATH_INFO to se
СредняяCVSS 5,3Эксплойта нетEPSS 2 %ordermanagementscript · professional service script27 дек. 2017 г.
- CVE-2017-1792421Наблюдать
PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via the id parameter to admin
СредняяCVSS 5,3Эксплойта нетEPSS 2 %ordermanagementscript · professional service script27 дек. 2017 г.
- CVE-2017-1792621Наблюдать
PHP Scripts Mall Professional Service Script has a predicable registration URL, which makes it easier for remote attackers to register with
СредняяCVSS 5,3Эксплойта нетEPSS 1 %ordermanagementscript · professional service script27 дек. 2017 г.
- CVE-2017-1792919Наблюдать
PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %ordermanagementscript · professional service script27 дек. 2017 г.
- CVE-2017-1792519Наблюдать
PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %ordermanagementscript · professional service script27 дек. 2017 г.