Записи virtual programming
10 опубликованных записей вендора virtual programming.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2003-0560Proof of concept | SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.virtual programming · vp-asp | Критическая10,0 | — | 3,2 % | 18 авг. 2003 г. |
30Наблюдать | CVE-2002-1919Эксплойта нет | SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and bypass authenticativirtual programming · vp-asp | Высокая7,5 | — | 1,5 % | 31 дек. 2002 г. |
30Наблюдать | CVE-2006-2263Proof of concept | SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands via the cid parametvirtual programming · vp-asp | Высокая7,5 | — | 1,4 % | 9 мая 2006 г. |
30Наблюдать | CVE-2004-2413Proof of concept | SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL commands via the (1) Prvirtual programming · vp-asp | Высокая7,5 | — | 1,2 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2004-2412Эксплойта нет | Multiple SQL injection vulnerabilities in VP-ASP Shopping Cart 4.0 through 5.0 allow remote attackers to execute arbitrary SQL commands via virtual programming · vp-asp | Высокая7,5 | — | 1,2 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2007-0224Proof of concept | SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary Svirtual programming · vp-asp | Высокая7,5 | — | 1,1 % | 12 янв. 2007 г. |
28Наблюдать | CVE-2007-0225Proof of concept | Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbvirtual programming · vp-asp | Средняя6,8 | — | 1,8 % | 12 янв. 2007 г. |
21Наблюдать | CVE-2004-2164Эксплойта нет | shoprestoreorder.asp in VP-ASP 5.0 does not close the database connection when a user restores a previous order, which allows remote attackevirtual programming · vp-asp | Средняя5,0 | — | 1,8 % | 31 дек. 2004 г. |
18Наблюдать | CVE-2004-2411Proof of concept | The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs, which allows remotvirtual programming · vp-asp | Средняя4,3 | — | 2,2 % | 31 дек. 2004 г. |
18Наблюдать | CVE-2005-3685Proof of concept | Cross-site scripting (XSS) vulnerability in shopadmin.asp in VP-ASP Shopping Cart 5.50 allows remote attackers to inject arbitrary web scripvirtual programming · vp-asp | Средняя4,3 | — | 1,9 % | 18 нояб. 2005 г. |
- CVE-2003-056041В плане
SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.
КритическаяCVSS 10,0Proof of conceptEPSS 3 %virtual programming · vp-asp18 авг. 2003 г.
- CVE-2002-191930Наблюдать
SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and bypass authenticati
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %virtual programming · vp-asp31 дек. 2002 г.
- CVE-2006-226330Наблюдать
SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands via the cid paramet
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %virtual programming · vp-asp9 мая 2006 г.
- CVE-2004-241330Наблюдать
SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL commands via the (1) Pr
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %virtual programming · vp-asp31 дек. 2004 г.
- CVE-2004-241230Наблюдать
Multiple SQL injection vulnerabilities in VP-ASP Shopping Cart 4.0 through 5.0 allow remote attackers to execute arbitrary SQL commands via
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %virtual programming · vp-asp31 дек. 2004 г.
- CVE-2007-022430Наблюдать
SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary S
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %virtual programming · vp-asp12 янв. 2007 г.
- CVE-2007-022528Наблюдать
Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arb
СредняяCVSS 6,8Proof of conceptEPSS 2 %virtual programming · vp-asp12 янв. 2007 г.
- CVE-2004-216421Наблюдать
shoprestoreorder.asp in VP-ASP 5.0 does not close the database connection when a user restores a previous order, which allows remote attacke
СредняяCVSS 5,0Эксплойта нетEPSS 2 %virtual programming · vp-asp31 дек. 2004 г.
- CVE-2004-241118Наблюдать
The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs, which allows remot
СредняяCVSS 4,3Proof of conceptEPSS 2 %virtual programming · vp-asp31 дек. 2004 г.
- CVE-2005-368518Наблюдать
Cross-site scripting (XSS) vulnerability in shopadmin.asp in VP-ASP Shopping Cart 5.50 allows remote attackers to inject arbitrary web scrip
СредняяCVSS 4,3Proof of conceptEPSS 2 %virtual programming · vp-asp18 нояб. 2005 г.