Записи shop-script
5 опубликованных записей вендора shop-script.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2007-4932Proof of concept | admin.php in Shop-Script FREE 2.0 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missshop-script · shop-script · CWE-20 | Высокая7,5 | — | 2,5 % | 18 сент. 2007 г. |
31Наблюдать | CVE-2007-4933Proof of concept | Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier allows remote attacshop-script · shop-script · CWE-94 | Высокая7,5 | — | 2,4 % | 18 сент. 2007 г. |
30Наблюдать | CVE-2007-2331Эксплойта нет | PHP remote file inclusion vulnerability in cart.php in Shop-Script 2.0 allows remote attackers to execute arbitrary PHP code via a URL in thshop-script · shop-script | Высокая7,5 | — | 1,4 % | 26 апр. 2007 г. |
27Наблюдать | CVE-2009-2023Proof of concept | SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbishop-script · shop-script · CWE-89 | Средняя6,8 | — | 1,0 % | 9 июн. 2009 г. |
21Наблюдать | CVE-2008-0158Proof of concept | Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary fileshop-script · shop-script · CWE-22 | Средняя5,0 | — | 2,1 % | 8 янв. 2008 г. |
- CVE-2007-493231Наблюдать
admin.php in Shop-Script FREE 2.0 and earlier sends a redirect to the web browser but does not exit when administrative credentials are miss
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %shop-script · shop-script18 сент. 2007 г.
- CVE-2007-493331Наблюдать
Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier allows remote attac
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %shop-script · shop-script18 сент. 2007 г.
- CVE-2007-233130Наблюдать
PHP remote file inclusion vulnerability in cart.php in Shop-Script 2.0 allows remote attackers to execute arbitrary PHP code via a URL in th
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %shop-script · shop-script26 апр. 2007 г.
- CVE-2009-202327Наблюдать
SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbi
СредняяCVSS 6,8Proof of conceptEPSS 1 %shop-script · shop-script9 июн. 2009 г.
- CVE-2008-015821Наблюдать
Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary file
СредняяCVSS 5,0Proof of conceptEPSS 2 %shop-script · shop-script8 янв. 2008 г.